public inbox for linux-newbie@vger.kernel.org
 help / color / mirror / Atom feed
From: Sanjay Arora <skpobox@yahoo.com>
To: linux-net@vger.kernel.org
Cc: linux-newbie@vger.kernel.org
Subject: Re: Linux Networking problem...please help..
Date: Wed, 16 Jul 2003 05:20:34 -0700 (PDT)	[thread overview]
Message-ID: <20030716122034.88944.qmail@web21001.mail.yahoo.com> (raw)
In-Reply-To: <3F1332FC.8080903@bcgreen.com>

Netmask is 255.255.255.0 on all machines.

Point is that the WinXP machine is being given a
redirect by the Linux firewall and that is being
ignored, either due to inability of WinXP or some
misconfiguration by me.

Sanjay.

--- Stephen Samuel <samuel@bcgreen.com> wrote:
> What are the netmasks for the two machines?? If you
> give them a /18
> (or a /16) netmask and the associated broadcast
> addresses, then they'll
> know to just talk directly to each other.
> 
> Of course, I barely trust Windows to understand
> netmasks, but it
> should be OK -- far better than trying to get it to
> accept ICMP
> redirects.
> 
> 
> Sanjay Arora wrote:
> > Network Scenario: RH 8 Linux Firewall Server using
> three ethernet cards, 
> > IPs 172.16.0.141 (connected to Cable Ethernet ISP
> doing NAT), 
> > 192.168.200.1 connected to an ethernet hub, &
> 192.168.100.1 (presently 
> > not being used). Using a hub two lans are
> connected to 192.168.200.1, 
> > each presently having one machine each having IP
> addresses 192.168.200.2 
> > (Windows XP machine, having Gateway address of
> 192.168.200.1 in TCP/IP 
> > settings) and 192.168.250.1 (RH8 Linux Server,
> again having 
> > 192.168.200.1 as GW address).
> > 
> > 1. When I ftp from 192.168.200.2 (WinXP) to
> 192.168.250.1 (RH Linux File 
> > Server), the firewall shows an error message
> saying that WinXP machine 
> > is ignoring redirects to 192.168.250.1 The
> transfer speed is also around 
> > 3.5 MB instead of full 10 MB which I get between
> the two Linux Servers. 
> > What's the reason? What do I do to correct this
> behaviour?
> > 
> > 2. The RH fileserver machine is very
> underutilized. I am thinking of 
> > putting another ethernet card in it and connect is
> to the cable ISP and 
> > Firewall server using a hub. I plan to put a
> firewall on the new 
> > ethernet/IP address denying all outgoing packets
> and put a sniffer on 
> > it. What are the security implications of this?
> Mind the IP that sniffer 
> > is running on is denying all outgoing traffic and
> dropping all incoming 
> > traffic and providing no services at all. On the
> other hand the machine 
> > is inside the firewall.... a compromise here would
> provide direct access 
> > to all local network resources. Is a compromise
> possible on an IP that 
> > denies all traffic inbound and outbound? Should I
> waste one machine for 
> > this task on my proposed small network (less than
> 20 machines)?
> > 
> > With thanks in advance ;-))
> > Sanjay.
> 
> 
> -- 
> Stephen Samuel +1(604)876-0426               
> samuel@bcgreen.com
> 		   http://www.bcgreen.com/~samuel/
>     Powerful committed communication. Transformation
> touching
>         the jewel within each person and bring it to
> life.
> 


__________________________________
Do you Yahoo!?
SBC Yahoo! DSL - Now only $29.95 per month!
http://sbc.yahoo.com

       reply	other threads:[~2003-07-16 12:20 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <3F1332FC.8080903@bcgreen.com>
2003-07-16 12:20 ` Sanjay Arora [this message]
2003-07-16 14:06   ` Linux Networking problem...please help Ray Olszewski
2003-07-16 15:00   ` Sven Schuster
2003-07-16 15:16     ` Sven Schuster
2003-07-17 15:09   ` Liam Helmer
2003-07-16 17:45 beolach
  -- strict thread matches above, loose matches on Subject: below --
2003-07-13 18:41 Sanjay Arora
2003-07-13 21:52 ` Ray Olszewski
2003-07-14  2:41 ` Glynn Clements

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20030716122034.88944.qmail@web21001.mail.yahoo.com \
    --to=skpobox@yahoo.com \
    --cc=linux-net@vger.kernel.org \
    --cc=linux-newbie@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox