Re: [SLE] SuSE 10.0 masquerade changes?

From: Darryl Gregorash (raven_at_accesscomm.ca)
Date: 11/17/05

  • Next message: Allen: "Re: [SLE] ...and speaking of SuSE / Novell..."
    Date: Wed, 16 Nov 2005 22:10:14 -0600
    To: suse-linux-e@suse.com
    
    

    On 11/16/2005 11:11 AM, Peter A. Taylor wrote:
    >On Tuesday 15 November 2005 19:36, Darryl Gregorash wrote:
    >
    >>I'm even more confused:
    >>
    >>>Nov 15 09:05:49 athena kernel: SFW2-FWDint-DROP-DEFLT IN=eth0 OUT=modem0
    >>>SRC=192.168.2.20 DST=64.243.71.82 LEN=73 TOS=0x00 PREC=0x00 TTL=127
    >>>ID=33119 PROTO=UDP SPT=1027 DPT=53 LEN=53
    >>>
    >>This is a DNS lookup from "isis" that was just dropped, yet you say your
    >>wife is able to resolve hostnames.
    >>
    >
    > "isis" runs Windows XP Home Edition. Perhaps it caches recently used domain
    >name data? It also has a modem, which she can't use when I'm online.
    >
    OK, that might be the reason she can resolve the ISP's ftp server, but
    it doesn't explain why her network traffic is being dropped. Note also
    that name caching is only temporary, and if your internal network was a
    permanent fixture (ie if she had no modem of her own), I am pretty sure
    she would be unable to resolve any hostnames.
    > Output from SuSE 10.0, online, "iptables -L -n":
    Mea culpa; there are actually 3 independent tables in the firewall
    (filter, nat and mangle), and the command as I gave it to you only gives
    the state of the "filter" table. All the masquerading rules are in the
    "nat" table. Perhaps we really need to be looking at the raw rules
    anyway, for which there is the "iptables-save" command. Each line of the
    output is essentially the parameters of a single "iptables" commandline
    as the firewall script created it. Just run "iptables-save" as root,
    with no parameters, and post the results. This command outputs all three
    of the tables by default.

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Allen: "Re: [SLE] ...and speaking of SuSE / Novell..."

    Relevant Pages

    • RE: SBS 2003 Fax Service - Cant "Pause Printing" and ...
      ... I'm glad we resolve the outbound fax always go through one modem issue. ... Now, you get error when you try to stop fax from Server Management console, ... Gather MPS network report on SBS: ...
      (microsoft.public.windows.server.sbs)
    • RE: Sierra Wireless (MC8780) HSDPA speed issue
      ... I have solved the modem hangup issues when using the AT control device ... The problem appears to be the AT&C1 command. ... Three devices appear, ttyUSB0, ttyUSB1, ttyUSB2. ... I have successfully reached average download speeds above 400KB/s. ...
      (Linux-Kernel)
    • trace ip
      ... Ascend digital modem box, his last attack I logged he tried 15 or so ... easy to see from the out side or make the security really LAX on that comp. ... It is all command ...
      (microsoft.public.security)
    • Re: trace ip
      ... > How can I trace someone trying to hack my ascend digital vpn modem? ... > authentication and is being logged into our RAD logs. ... > to c:\) So it will look like this in command ... Anyway I am not too worried about security ...
      (microsoft.public.security)
    • Re: Modem genius wanted
      ... You really need an AT command set, and to read the thing end to end! ... From my old modem manual ... ... ATV1 Result codes as words <- You probably want this ... Dialling is blind, regardless of dial tone. ...
      (sci.electronics.design)

    Loading