All of lore.kernel.org
 help / color / mirror / Atom feed
* voice IP
@ 2003-11-03 20:25 Manuel Tato
  2003-11-03 15:01 ` Herman
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Manuel Tato @ 2003-11-03 20:25 UTC (permalink / raw)
  To: netfilter

i have this firewall, i have at 192.168.1.40 a voice ip gateway, i'm 
doing portforward to this ip.
i make phone calls with out major problems, but i can´t recive any...
someone have voip experience trough linux fw/routers?
thanks in advance
manuel


#!/bin/bash
# eth1--> Modem/ADSL
# eth0--> LAN
#
echo 1 > /proc/sys/net/ipv4/ip_forward
modprobe ipt_MASQUERADE
modprobe ip_conntrack
modprobe ip_conntrack_ftp
modprobe iptable_nat
modprobe ip_conntrack_h323
modprobe ip_nat_h323
#
iptables -F
iptables -t nat -F
iptables -t mangle -F
iptables -A INPUT -j ACCEPT
iptables -A FORWARD -j ACCEPT
iptables -A OUTPUT -j ACCEPT

iptables -A FORWARD -p tcp --sport 137:139 -j DROP
iptables -A FORWARD -p udp --sport 137:139 -j DROP
#    NFS Mount Service (TCP/UDP 635)
iptables -A FORWARD -p tcp --sport 635 -j DROP
iptables -A FORWARD -p udp --sport 635 -j DROP
#    NFS (TCP/UDP 2049)
iptables -A FORWARD -p tcp --sport 2049 -j DROP
iptables -A FORWARD -p udp --sport 2049 -j DROP
#    Portmapper (TCP/UDP 111)
iptables -A FORWARD -p tcp --sport 111 -j DROP
iptables -A FORWARD -p udp --sport 111 -j DROP
# Block incoming syslog, lpr, rsh, rexec...
iptables -A FORWARD -i eth1 -p udp --dport syslog -j DROP
iptables -A FORWARD -i eth1 -p tcp --dport 515 -j DROP
iptables -A FORWARD -i eth1 -p tcp --dport 514 -j DROP
iptables -A FORWARD -i eth1 -p tcp --dport 512 -j DROP
###
#
# NAT
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
######
#####
#######
iptables -A FORWARD -p tcp --sport 1719:1789 -j ACCEPT
iptables -A FORWARD -p udp --sport 1719:1789 -j ACCEPT

iptables -t nat -A PREROUTING -p tcp --dport 80 -i eth1 -j DNAT --to 
192.168.1.40:80
iptables -A FORWARD -i eth1 -p tcp -d 192.168.1.40 --dport 80 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp --dport 23 -i eth1 -j DNAT --to 
192.168.1.40:23
iptables -A FORWARD -i eth1 -p tcp -d 192.168.1.40 --dport 23 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp --dport 161 -i eth1 -j DNAT --to 
192.168.1.40:161
iptables -A FORWARD -i eth1 -p tcp -d 192.168.1.40 --dport 161 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp --dport 1726:1789 -i eth1 -j DNAT 
--to 192.168.1.40:1726:1789
iptables -A FORWARD -i eth1 -p tcp -d 192.168.1.40 --dport 1726:1789 -j 
ACCEPT
iptables -t nat -A PREROUTING -p udp --dport 1726:1789 -i eth1 -j DNAT 
--to 192.168.1.40:1726:1789
iptables -A FORWARD -i eth1 -p udp -d 192.168.1.40 --dport  1726:1789 -j 
ACCEPT






^ permalink raw reply	[flat|nested] 8+ messages in thread
* RE: Voice IP
@ 2003-10-27 21:51 George Vieira
  0 siblings, 0 replies; 8+ messages in thread
From: George Vieira @ 2003-10-27 21:51 UTC (permalink / raw)
  To: Manuel Tato, netfilter

I have this working at home using these rules...


        if [ $H323 ]; then
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 389    -j DNAT --to 192.168.1.1        # H323
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 522    -j DNAT --to 192.168.1.1        # H323
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1503   -j DNAT --to 192.168.1.1        # H323
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1720   -j DNAT --to 192.168.1.1        # H323
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1731   -j DNAT --to 192.168.1.1        # H323
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 8080   -j DNAT --to 192.168.1.1        # H323
                $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1469   -j DNAT --to 192.168.1.1        # H323aud
        fi

What I did notice is that I couldn't get people to call me unless I was in a meeting call or something (soz, it's been months since I've used netmeeting ;) )...

Thanks,
____________________________________________
George Vieira
Systems Manager
georgev@citadelcomputer.com.au

Citadel Computer Systems Pty Ltd
http://www.citadelcomputer.com.au

Phone   : +61 2 9955 2644
HelpDesk: +61 2 9955 2698
 

> -----Original Message-----
> From: Manuel Tato [mailto:madness@adinet.com.uy]
> Sent: Tuesday, 28 October 2003 8:35 AM
> To: netfilter@lists.netfilter.org
> Subject: Voice IP
> 
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> 
> Hi, i'm configuring a firewall/router with a static ip ADSL 
> and a voice
> IP gateway.
> The voiceip gw es in configured at 192.168.1.40.
> With this script i can make calls, but i cant recive any.
> 
> - ---------------------------------------------------
> echo 1 > /proc/sys/net/ipv4/ip_forward
> 
> modprobe ip_conntrack_h323
> modprobe ip_nat_h323
> 
> iptables -A INPUT -j ACCEPT
> iptables -A FORWARD -j ACCEPT
> iptables -A OUTPUT -j ACCEPT
> 
> iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
> 
> iptables -t nat -A PREROUTING -p tcp --dport 1726:1789 -i eth1 -j DNAT
> - --to 192.168.1.40:1726:1789
> iptables -A FORWARD -i eth1 -p tcp -d 192.168.1.40 --dport 
> 1726:1789 -j
> ACCEPT
> iptables -t nat -A PREROUTING -p udp --dport 1726:1789 -i eth1 -j DNAT
> - --to 192.168.1.40:1726:1789
> iptables -A FORWARD -i eth1 -p udp -d 192.168.1.40 --dport  
> 1726:1789 -j
> ACCEPT
> - -----------------------------------------------------
> 
> Any idea?
> i'm blocking ports?
> i need any other module??
> thanks in advance
> thanks a lot...
> 
> 
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.2.2 (MingW32)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
> 
> iD8DBQE/nY98W/G6GKzQKp4RAndEAJ4pYh04AZuTc/f8MQ8Ae6RB/GpRFgCgkaCg
> SwAh5HHLSdd0rj68FzTPdXY=
> =RcOK
> -----END PGP SIGNATURE-----
> 
> 
> 
> 


^ permalink raw reply	[flat|nested] 8+ messages in thread
* Voice IP
@ 2003-10-27 21:34 Manuel Tato
  2003-10-27 21:50 ` Evan Davies
  0 siblings, 1 reply; 8+ messages in thread
From: Manuel Tato @ 2003-10-27 21:34 UTC (permalink / raw)
  To: netfilter

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hi, i'm configuring a firewall/router with a static ip ADSL and a voice
IP gateway.
The voiceip gw es in configured at 192.168.1.40.
With this script i can make calls, but i cant recive any.

- ---------------------------------------------------
echo 1 > /proc/sys/net/ipv4/ip_forward

modprobe ip_conntrack_h323
modprobe ip_nat_h323

iptables -A INPUT -j ACCEPT
iptables -A FORWARD -j ACCEPT
iptables -A OUTPUT -j ACCEPT

iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE

iptables -t nat -A PREROUTING -p tcp --dport 1726:1789 -i eth1 -j DNAT
- --to 192.168.1.40:1726:1789
iptables -A FORWARD -i eth1 -p tcp -d 192.168.1.40 --dport 1726:1789 -j
ACCEPT
iptables -t nat -A PREROUTING -p udp --dport 1726:1789 -i eth1 -j DNAT
- --to 192.168.1.40:1726:1789
iptables -A FORWARD -i eth1 -p udp -d 192.168.1.40 --dport  1726:1789 -j
ACCEPT
- -----------------------------------------------------

Any idea?
i'm blocking ports?
i need any other module??
thanks in advance
thanks a lot...


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE/nY98W/G6GKzQKp4RAndEAJ4pYh04AZuTc/f8MQ8Ae6RB/GpRFgCgkaCg
SwAh5HHLSdd0rj68FzTPdXY=
=RcOK
-----END PGP SIGNATURE-----




^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2003-11-04  8:33 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-03 20:25 voice IP Manuel Tato
2003-11-03 15:01 ` Herman
2003-11-03 20:55 ` Manuel Tato
2003-11-03 21:38 ` Jörg Schütter
2003-11-04  8:33 ` Thierry ITTY
  -- strict thread matches above, loose matches on Subject: below --
2003-10-27 21:51 Voice IP George Vieira
2003-10-27 21:34 Manuel Tato
2003-10-27 21:50 ` Evan Davies

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.