Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Rowan Reid <rreid@studio3arc.com>
To: 'Antony Stone' <Antony@Soft-Solutions.co.uk>,
	netfilter@lists.netfilter.org
Subject: RE: Internal ip exiting network on firewall external nic despight rule
Date: Fri, 20 Sep 2002 16:10:40 -0700	[thread overview]
Message-ID: <000301c260fa$f0b68860$0801a8c0@s3ac> (raw)
In-Reply-To: <20020920224321.VUFI295.mta06-svc.ntlworld.com@there>




> > Just when I thought I understood. So returning masqaraded 
> traffic hits 
> > the input rule set no ?
> 
> No :-)

Dooope !!

> 
> > Then gets routed through POSTROUTING
> 
> No :-)

Doooope !!!
> 
> > is it then routed to the forward ruleset, or is it just sent out.
> 
> Okay - this is how it works:
> 
> The *original* packet (the first one) in what is going to be a natted 
> connection gets to the firewall, enters the PREROUTING chain, and the 
> destination address gets changed.   The packet then goes on 
> to the FORWARD

So it gets nated at the PREROUTING chain oooooooohhhhhhhh ...
> 1. The INPUT chain is *only* for packets which terminate on 
> this machine.
> 
> 2. The FORWARD chain is *only* for packets which are going 
> through this 
> machine.
> 
> 3. The OUTPUT chain is *only* for packets which originate on 
> this machine.


Ooooooooooooohhhhhhhhhhhhhhhhhhhhhhhhh !!

> 
> > Then figure out why exactly my local net machines are accessing my 
> > external IP to exit the net. This confuses me because all these 
> > machines are setup with the gateway being the internal ip
> > (192.168.1.1/255.255.255.0) as the gateway so these 
> machines shouldn't 
> > even know my external ip/interface exists.
> 
> You have physically plugged the internal and external 
> interfaces of your 
> firewall into the same switch / hub, therefore the machines 
> on your internal 
> network are plugged into your external interface, and 
> unfortunately Linux 
> responds to ARP requests in ways you might not expect....  (I 
> think Tom 
> Eastep mentioned this in an earlier posting).
> 
> Connect your external interface to your Internet link, using 
> a switch / hub 
> which also has any other machines with true (non-nat) public IPs.

Oohh ok .. Well

Thank you thank you thank you thank you thank you, for your time I
appreciate that .. Domo arigato genious san.

<action> 
Goes back to my mlafunctioned misconfigured linux box 
</action>



  reply	other threads:[~2002-09-20 23:10 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-09-20 18:37 Internal ip exiting network on firewall external nic despight rule Rowan Reid
2002-09-20 19:05 ` Antony Stone
2002-09-20 20:59   ` Rowan Reid
2002-09-20 21:36     ` Antony Stone
2002-09-20 21:58       ` Rowan Reid
2002-09-20 22:43         ` Antony Stone
2002-09-20 23:10           ` Rowan Reid [this message]
2002-09-20 23:32             ` Antony Stone
2002-09-20 19:13 ` Tom Eastep
2002-09-20 19:11   ` Rowan Reid
2002-09-20 19:34     ` Antony Stone
2002-09-20 19:40       ` Tom Eastep
2002-09-20 21:24       ` Rowan Reid
2002-09-20 21:54         ` Antony Stone
2002-09-20 22:26           ` Rowan Reid
2002-09-20 23:01             ` Antony Stone
2002-09-20 23:13               ` Rowan Reid
2002-09-20 23:37                 ` Antony Stone
2002-09-21  1:00                 ` Tom Eastep
2002-09-21 13:01             ` Anders Fugmann
2002-09-20 19:36     ` Tom Eastep
2002-09-20 19:53     ` Alistair Tonner
     [not found] <000d01c260e8$df710380$0801a8c0@s3ac>
2002-09-20 21:44 ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='000301c260fa$f0b68860$0801a8c0@s3ac' \
    --to=rreid@studio3arc.com \
    --cc=Antony@Soft-Solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox