From: Rowan Reid <rreid@studio3arc.com>
To: 'Antony Stone' <Antony@Soft-Solutions.co.uk>,
netfilter@lists.netfilter.org
Subject: RE: Internal ip exiting network on firewall external nic despight rule
Date: Fri, 20 Sep 2002 16:10:40 -0700 [thread overview]
Message-ID: <000301c260fa$f0b68860$0801a8c0@s3ac> (raw)
In-Reply-To: <20020920224321.VUFI295.mta06-svc.ntlworld.com@there>
> > Just when I thought I understood. So returning masqaraded
> traffic hits
> > the input rule set no ?
>
> No :-)
Dooope !!
>
> > Then gets routed through POSTROUTING
>
> No :-)
Doooope !!!
>
> > is it then routed to the forward ruleset, or is it just sent out.
>
> Okay - this is how it works:
>
> The *original* packet (the first one) in what is going to be a natted
> connection gets to the firewall, enters the PREROUTING chain, and the
> destination address gets changed. The packet then goes on
> to the FORWARD
So it gets nated at the PREROUTING chain oooooooohhhhhhhh ...
> 1. The INPUT chain is *only* for packets which terminate on
> this machine.
>
> 2. The FORWARD chain is *only* for packets which are going
> through this
> machine.
>
> 3. The OUTPUT chain is *only* for packets which originate on
> this machine.
Ooooooooooooohhhhhhhhhhhhhhhhhhhhhhhhh !!
>
> > Then figure out why exactly my local net machines are accessing my
> > external IP to exit the net. This confuses me because all these
> > machines are setup with the gateway being the internal ip
> > (192.168.1.1/255.255.255.0) as the gateway so these
> machines shouldn't
> > even know my external ip/interface exists.
>
> You have physically plugged the internal and external
> interfaces of your
> firewall into the same switch / hub, therefore the machines
> on your internal
> network are plugged into your external interface, and
> unfortunately Linux
> responds to ARP requests in ways you might not expect.... (I
> think Tom
> Eastep mentioned this in an earlier posting).
>
> Connect your external interface to your Internet link, using
> a switch / hub
> which also has any other machines with true (non-nat) public IPs.
Oohh ok .. Well
Thank you thank you thank you thank you thank you, for your time I
appreciate that .. Domo arigato genious san.
<action>
Goes back to my mlafunctioned misconfigured linux box
</action>
next prev parent reply other threads:[~2002-09-20 23:10 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-09-20 18:37 Internal ip exiting network on firewall external nic despight rule Rowan Reid
2002-09-20 19:05 ` Antony Stone
2002-09-20 20:59 ` Rowan Reid
2002-09-20 21:36 ` Antony Stone
2002-09-20 21:58 ` Rowan Reid
2002-09-20 22:43 ` Antony Stone
2002-09-20 23:10 ` Rowan Reid [this message]
2002-09-20 23:32 ` Antony Stone
2002-09-20 19:13 ` Tom Eastep
2002-09-20 19:11 ` Rowan Reid
2002-09-20 19:34 ` Antony Stone
2002-09-20 19:40 ` Tom Eastep
2002-09-20 21:24 ` Rowan Reid
2002-09-20 21:54 ` Antony Stone
2002-09-20 22:26 ` Rowan Reid
2002-09-20 23:01 ` Antony Stone
2002-09-20 23:13 ` Rowan Reid
2002-09-20 23:37 ` Antony Stone
2002-09-21 1:00 ` Tom Eastep
2002-09-21 13:01 ` Anders Fugmann
2002-09-20 19:36 ` Tom Eastep
2002-09-20 19:53 ` Alistair Tonner
[not found] <000d01c260e8$df710380$0801a8c0@s3ac>
2002-09-20 21:44 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='000301c260fa$f0b68860$0801a8c0@s3ac' \
--to=rreid@studio3arc.com \
--cc=Antony@Soft-Solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox