From mboxrd@z Thu Jan 1 00:00:00 1970 From: "j-michel.caricand" Subject: H323 Date: Wed, 12 Jun 2002 07:08:22 +0200 Sender: netfilter-admin@lists.samba.org Message-ID: <001501c211cf$2d576580$0103a8c0@gretabesancon.fr> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0012_01C211DF.F0385CC0" Return-path: Errors-To: netfilter-admin@lists.samba.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.samba.org C'est un message de format MIME en plusieurs parties. ------=_NextPart_000_0012_01C211DF.F0385CC0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello, I am a serious problem this my gateway. I must apply the = newnat/h323 patch for use netmetting.=20 I have following the steps of the patch-o-matic DOC, but I can not apply = the patch.=20 I have kernel 2.4.18 installed. I get all patches from CVS=20 I follow your documentation to do that=20 but ...=20 Do you want to apply this patch [N/y/t/f/a/r/b/w/v/q/?] t ... FAILED... ... This very important for me ! HELP !!! ------=_NextPart_000_0012_01C211DF.F0385CC0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Hello, I am a serious problem = this my gateway.=20 I must apply the newnat/h323 patch for use netmetting.
I have = following=20 the steps of the patch-o-matic DOC, but I can not apply = the patch.=20
 
I have kernel 2.4.18 = installed.
I get all patches from CVS =
I follow your documentation to do that=20
 
but ...

Do you want to apply = this patch=20 [N/y/t/f/a/r/b/w/v/q/?] t
...
FAILED...
...
 
This very important for me ! HELP=20 !!!
------=_NextPart_000_0012_01C211DF.F0385CC0-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Toshihiro Sonoda" Subject: Re: h323 Date: Mon, 23 Sep 2002 02:35:11 +0900 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000f01c2625e$6797ba80$abf8a8c0@monday> References: <3D8DF73A.7020408@iol.it> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Iptables has h323 modules, too. You have to apply kernel-patch of patch-o-matic. But, I think h323 modules is not perfect... > Hi > > I am on a LAN which access to the Internet with a NAT on a gateway Linux > server configured with iptables. > How I can use on a client inside the LAN a program which uses h323 > protocol, for example Microsoft Netmeeting? I wish to correctly use > text, audio and video features of Netmeeting, and I wish to call and to > be called. > > How I can configure the firewall on the gateway server? > I rememeber that for ipchains there was an h323 module. There is > anything for iptables too? > > Thank you very much > Bye > Mattia Martinello > m.martinello@iol.it > > > > From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mattia Martinello Subject: h323 Date: Sun, 22 Sep 2002 19:00:42 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <3D8DF73A.7020408@iol.it> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: netfilter@lists.netfilter.org Hi I am on a LAN which access to the Internet with a NAT on a gateway Linux server configured with iptables. How I can use on a client inside the LAN a program which uses h323 protocol, for example Microsoft Netmeeting? I wish to correctly use text, audio and video features of Netmeeting, and I wish to call and to be called. How I can configure the firewall on the gateway server? I rememeber that for ipchains there was an h323 module. There is anything for iptables too? Thank you very much Bye Mattia Martinello m.martinello@iol.it From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Diego R. Rodriguez Herlein" Subject: Re: h323 Date: Sun, 22 Sep 2002 15:13:21 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <003e01c26263$bcbef230$8201a8c0@lw1dqwin> References: <3D8DF73A.7020408@iol.it> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Mattia Martinello , netfilter@lists.netfilter.org Hi, sorry about my english. I use kernel 2.4.17 with the newnat patch and h323 work great ! Regards, Diego ----- Original Message ----- From: "Mattia Martinello" To: Sent: Sunday, September 22, 2002 2:00 PM Subject: h323 > Hi > > I am on a LAN which access to the Internet with a NAT on a gateway Linux > server configured with iptables. > How I can use on a client inside the LAN a program which uses h323 > protocol, for example Microsoft Netmeeting? I wish to correctly use > text, audio and video features of Netmeeting, and I wish to call and to > be called. > > How I can configure the firewall on the gateway server? > I rememeber that for ipchains there was an h323 module. There is > anything for iptables too? > > Thank you very much > Bye > Mattia Martinello > m.martinello@iol.it > > > From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Toshihiro Sonoda" Subject: Re: h323 Date: Mon, 23 Sep 2002 10:45:24 +0900 Sender: netfilter-admin@lists.netfilter.org Message-ID: <001d01c262a2$e2cbdb70$ccf8a8c0@monday> References: <3D8DF73A.7020408@iol.it> <003e01c26263$bcbef230$8201a8c0@lw1dqwin> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Hi, Diego. I have questions. does the new nat patch have h.225ras, or ldap for NAT problems. before, when i applied the h.323 patch, the patchs have a part of h.323, but not h.225. Is that ok? Can you use ILS server, or Gatekeeper? > Hi, > sorry about my english. > I use kernel 2.4.17 with the newnat patch and h323 work great ! > Regards, > > Diego > > > ----- Original Message ----- > From: "Mattia Martinello" > To: > Sent: Sunday, September 22, 2002 2:00 PM > Subject: h323 > > > > Hi > > > > I am on a LAN which access to the Internet with a NAT on a gateway Linux > > server configured with iptables. > > How I can use on a client inside the LAN a program which uses h323 > > protocol, for example Microsoft Netmeeting? I wish to correctly use > > text, audio and video features of Netmeeting, and I wish to call and to > > be called. > > > > How I can configure the firewall on the gateway server? > > I rememeber that for ipchains there was an h323 module. There is > > anything for iptables too? > > > > Thank you very much > > Bye > > Mattia Martinello > > m.martinello@iol.it > > > > > > > > From mboxrd@z Thu Jan 1 00:00:00 1970 From: Jozsef Kadlecsik Subject: Re: h323 Date: Mon, 23 Sep 2002 12:27:35 +0200 (CEST) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <001d01c262a2$e2cbdb70$ccf8a8c0@monday> Mime-Version: 1.0 Return-path: In-Reply-To: <001d01c262a2$e2cbdb70$ccf8a8c0@monday> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Toshihiro Sonoda Cc: netfilter@lists.netfilter.org On Mon, 23 Sep 2002, Toshihiro Sonoda wrote: > does the new nat patch have h.225ras, or ldap for NAT problems. The h323 patch does not support RAS. > before, when i applied the h.323 patch, the patchs > have a part of h.323, but not h.225. > Is that ok? Yes, that's OK. > Can you use ILS server, or Gatekeeper? The h323 patch does not support gatekeepers. Regards, Jozsef - E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : KFKI Research Institute for Particle and Nuclear Physics H-1525 Budapest 114, POB. 49, Hungary From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Rimas" Subject: patch-o-matic: newnat and h323 Date: Wed, 25 Sep 2002 11:03:39 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <02af01c2647a$d3f37250$6e69690a@rimas> References: <3D8DF73A.7020408@iol.it> <003e01c26263$bcbef230$8201a8c0@lw1dqwin> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Hi, What "patch-o-matic" patches I have to install for "newnat" and "h323" patches on kernel 2.4.19? Regards Rimas From mboxrd@z Thu Jan 1 00:00:00 1970 From: Fabrice MARIE Subject: Re: patch-o-matic: newnat and h323 Date: Wed, 25 Sep 2002 18:34:51 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200209251834.51533.fabrice@celestix.com> References: <3D8DF73A.7020408@iol.it> <003e01c26263$bcbef230$8201a8c0@lw1dqwin> <02af01c2647a$d3f37250$6e69690a@rimas> Reply-To: fabrice@celestix.com Mime-Version: 1.0 Content-Transfer-Encoding: 8bit Return-path: In-Reply-To: <02af01c2647a$d3f37250$6e69690a@rimas> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Rimas , netfilter@lists.netfilter.org On Wednesday 25 September 2002 18:03, Rimas wrote: > Hi, > What "patch-o-matic" patches I have to install for "newnat" and "h323" > patches on kernel 2.4.19? > Regards > Rimas Hello Rimas, Install the p-o-m patches in pending (this includes but is not limited to newnat). Then install extra/h323-conntrack-nat.patch If you don't know how to use p-o-m, then you can read the netfilter-extensions-HOWTO: http://www.netfilter.org/documentation/HOWTO/netfilter-extensions-HOWTO.html ./runme --batch pending ./runme extra/h323-conntrack-nat.patch should do the trick. Have a nice day, Fabrice. -- Fabrice MARIE Senior R&D Engineer Celestix Networks http://www.celestix.com/ "Silly hacker, root is for administrators" -Unknown From mboxrd@z Thu Jan 1 00:00:00 1970 From: Rohan Almeida Subject: Re: patch-o-matic: newnat and h323 Date: Wed, 25 Sep 2002 17:47:19 +0530 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20020925174719.2aa01de2.arc_of_descent@gmx.net> References: <3D8DF73A.7020408@iol.it> <003e01c26263$bcbef230$8201a8c0@lw1dqwin> <02af01c2647a$d3f37250$6e69690a@rimas> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <02af01c2647a$d3f37250$6e69690a@rimas> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org "Rimas" thus wrote: > What "patch-o-matic" patches I have to install for "newnat" and "h323" > patches on kernel 2.4.19? HI, I had posted this earlier o I used the following patches of pom ahesp-static.patch arptables.patch config-cleanup.patch conntrack+nat-helper-unregister.patch conntrack.patch dscp.patch DSCP.patch ecn.patch ECN.patch helper.patch ip_conntrack_protocol_destroy.patch ip_conntrack_protocol_unregister.patch local-nat.patch macro-trailing-semicolon-fix.patch nat-export_symbols.patch nat-memoryleak-fix.patch netfilter-arp.patch z-newnat16.patch eggdrop-conntrack.patch h323-conntrack-nat.patch pptp-conntrack-nat.patch I expereinced problems with the z-newnat16.patch, but the above sequence works fine with me. Most important, remember "not" to apply the connmark patch I don't know why, maybe somebody can clarify this. -- arc_of_descent From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Tim" Subject: H323 Date: Thu, 21 Nov 2002 10:19:59 -0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <001701c2918a$9ab0af20$0b00a8c0@timboss> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0014_01C29147.8BB47440" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0014_01C29147.8BB47440 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi, just wondering if anyone has the same problem. Fresh copy of 2.4.19 and iptables 1.2.7a with patch-o-matic and used the = z-newnat and h323 that comes with it.. fixed the newnat patch which = couldn't load. add 2 lines to a ip_conntrack.h file and it worked fine. = We send audio fine but can't receive it.. possibly the same problem with = video too... Tim ------=_NextPart_000_0014_01C29147.8BB47440 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable

Hi, just wondering if anyone has the same=20 problem.

Fresh copy of 2.4.19 and iptables 1.2.7a with = patch-o-matic=20 and used the z-newnat and h323 that comes with it.. fixed the newnat patch which couldn't load. add 2 lines to = a=20 ip_conntrack.h file and it worked fine. We = send audio=20 fine but can't receive it.. possibly the same problem with video=20 too...

Tim

------=_NextPart_000_0014_01C29147.8BB47440-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Esteban Ribicic Subject: h323 Date: 13 Feb 2003 12:09:22 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1045148962.18435.31.camel@debian> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org hi, ive got a network masqueraded by iptables to internet. my clients (the one who are masqueraded) ask me for neetmeting and h323 stuff that does not work....does the h323 module for iptables permit such transmissions? or should i try to set a h323gatekeeper on the firewall? thanks esteban From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?iso-8859-1?Q?Rasmus_B=F8g_Hansen?= Subject: Re: h323 Date: Fri, 14 Feb 2003 10:17:02 +0100 (CET) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <1045148962.18435.31.camel@debian> Mime-Version: 1.0 Content-Transfer-Encoding: QUOTED-PRINTABLE Return-path: In-Reply-To: <1045148962.18435.31.camel@debian> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="iso-8859-1" To: Esteban Ribicic Cc: netfilter@lists.netfilter.org On 13 Feb 2003, Esteban Ribicic wrote: > ive got a network masqueraded by iptables to internet. > my clients (the one who are masqueraded) ask me for neetmeting and h323 > stuff that does not work....does the h323 module for iptables permit > such transmissions? H.323 (including netmeeting) will work fine with the H323 modules. You cannot, however, use call servers (I don't remember, what they're called) along with NAT. /Rasmus --=20 -- [ Rasmus "M=F8ffe" B=F8g Hansen ] --------------------------------------= - "Microsoft spel chekar worgs grate!" ----------------------------------[ moffe at amagerkollegiet dot dk ] -- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Dhyanesh Ramaiya" Subject: H323 Date: Tue, 25 Feb 2003 17:37:38 +0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000a01c2dcdb$72762890$0223a8c0@satconet.com> References: <200302130146.37200.netfilter@newkirk.us> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200302130146.37200.netfilter@newkirk.us> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Greetings, I am running Redhat 7.3 with Linux kernel 2.4.20 with H323 applied (compiled in the kernel). However, I am still not able to get netmeeting working over the NAT server. Is there any detailed documentation that I could refer to? Also, is there any way I could get MSN voice chat and file transfers to work over NAT firewall? I am running iptables-1.2.6a-2 on my NAT firewall. I have a rule in my firewall script that is SNAT-ting all the internal traffic to the IP address of the ethernet card connected to the Internet. Please assist. Thank you very much. Dhyanesh Ramaiya dhyanesh@intafrica.com From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Eric Wood" Subject: Re: H323 Date: Tue, 25 Feb 2003 09:58:20 -0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <006501c2dcde$55feaf40$9100000a@intgrp.com> References: <000a01c2dcdb$72762890$0223a8c0@satconet.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter I think netfilter can do the job. You'll need a gatekeeper to do this: Here's a few: OpenGK gatekeeper translates between user aliases and IP addresses. Makes your life easier. OpenH232Proxy is a gatekeeper with built in proxy feature. It enables the routing through the gatekeeper of the RTP traffic (audio and video) and the T.120 traffic (data) so no traffic is directly exchanged between endpoints. (This one is not in the distro yet.) OpenMCU H.323 conferencing server lets you hold virtual conferences. simply connect to openmcu server instead of connecting to another gnomemeeting client, and you are ready to go. If installed on a firewall (and visible from both sides), openmcu can serve as a proxy. I've got OpenH232Proxy sort of working for my cams. http://openh323proxy.sourceforge.net/ -eric wood ----- Original Message ----- From: "Dhyanesh Ramaiya" To: Sent: Tuesday, February 25, 2003 9:37 AM Subject: H323 > Greetings, > > I am running Redhat 7.3 with Linux kernel 2.4.20 with H323 applied (compiled > in the kernel). However, I am still not able to get netmeeting working over > the NAT server. Is there any detailed documentation that I could refer to? > Also, is there any way I could get MSN voice chat and file transfers to work > over NAT firewall? I am running iptables-1.2.6a-2 on my NAT firewall. I have > a rule in my firewall script that is SNAT-ting all the internal traffic to > the IP address of the ethernet card connected to the Internet. > > Please assist. > > Thank you very much. > > Dhyanesh Ramaiya > dhyanesh@intafrica.com > From mboxrd@z Thu Jan 1 00:00:00 1970 From: Rasmus Reinholdt Nielsen Subject: Re: H323 Date: Sun, 02 Mar 2003 11:41:27 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <5.1.0.14.2.20030302113931.0252ceb8@of23sm3.kadnet.dom> References: <000a01c2dcdb$72762890$0223a8c0@satconet.com> Mime-Version: 1.0 Return-path: In-Reply-To: <006501c2dcde$55feaf40$9100000a@intgrp.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" Content-Transfer-Encoding: 7bit To: Eric Wood , netfilter Hi Does anybody know I can use one of these gatekeepers / proxys as a transparent proxy for the msn messenger ip telephone client? Thanks /Rasmus At 09:58 25-02-2003 -0500, Eric Wood wrote: >I think netfilter can do the job. You'll need a gatekeeper to do this: > >Here's a few: >OpenGK gatekeeper translates between user aliases and IP addresses. Makes >your life easier. >OpenH232Proxy is a gatekeeper with built in proxy feature. It enables the >routing through the gatekeeper of the RTP traffic (audio and video) and the >T.120 traffic (data) so no traffic is directly exchanged between endpoints. >(This one is not in the distro yet.) >OpenMCU H.323 conferencing server lets you hold virtual conferences. simply >connect to openmcu server instead of connecting to another gnomemeeting >client, and you are ready to go. If installed on a firewall (and visible >from both sides), openmcu can serve as a proxy. > > >I've got OpenH232Proxy sort of working for my cams. >http://openh323proxy.sourceforge.net/ > >-eric wood > > >----- Original Message ----- >From: "Dhyanesh Ramaiya" >To: >Sent: Tuesday, February 25, 2003 9:37 AM >Subject: H323 > > > > Greetings, > > > > I am running Redhat 7.3 with Linux kernel 2.4.20 with H323 applied >(compiled > > in the kernel). However, I am still not able to get netmeeting working >over > > the NAT server. Is there any detailed documentation that I could refer to? > > Also, is there any way I could get MSN voice chat and file transfers to >work > > over NAT firewall? I am running iptables-1.2.6a-2 on my NAT firewall. I >have > > a rule in my firewall script that is SNAT-ting all the internal traffic to > > the IP address of the ethernet card connected to the Internet. > > > > Please assist. > > > > Thank you very much. > > > > Dhyanesh Ramaiya > > dhyanesh@intafrica.com > > From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?iso-8859-1?Q?Rasmus_B=F8g_Hansen?= Subject: Re: H323 Date: Sun, 2 Mar 2003 13:40:36 +0100 (CET) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <5.1.0.14.2.20030302113931.0252ceb8@of23sm3.kadnet.dom> Mime-Version: 1.0 Content-Transfer-Encoding: QUOTED-PRINTABLE Return-path: In-Reply-To: <5.1.0.14.2.20030302113931.0252ceb8@of23sm3.kadnet.dom> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="iso-8859-1" To: Rasmus Reinholdt Nielsen Cc: netfilter On Sun, 2 Mar 2003, Rasmus Reinholdt Nielsen wrote: > Does anybody know I can use one of these gatekeepers / proxys as a > transparent proxy for the msn messenger ip telephone client? MSN telephoy does not use H.323 and therefore is not supported by iptables. IIRC MSN messenger can be configured to use a socks proxy like dante (http://www.inet.no/dante/). /Rasmus --=20 -- [ Rasmus "M=F8ffe" B=F8g Hansen ] --------------------------------------= - A wizard is never late, nor is he too early. He arrives precisely when he wants to -- Gandalf ----------------------------------[ moffe at amagerkollegiet dot dk ] -- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "gold gold" Subject: H323 Date: Sat, 19 Jul 2003 07:08:40 +0000 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; format=flowed; charset="us-ascii" Content-Transfer-Encoding: 7bit To: netfilter@lists.netfilter.org Hello everybody, I've already asked this question before, but here it is again: How do I enable my masqueraded Windows machine to use MSN's audio/video conversation? I've been told to load the "H323" module and do some "patch-o-matic stuff" (??), but I don't really know alot about these stuff... could someone please give me detailed step-by-step instructions on how to do that? I would really appreciate this. Thanks a lot. _________________________________________________________________ The new MSN 8: smart spam protection and 2 months FREE* http://join.msn.com/?page=features/junkmail From mboxrd@z Thu Jan 1 00:00:00 1970 From: Emanoil Kotsev Subject: Re: H323 Date: Sun, 20 Jul 2003 11:13:15 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200307201113.25976.emanuel@abc.at> References: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: Content-Description: clearsigned data Content-Disposition: inline Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: Text/Plain; charset="us-ascii" To: gold gold , netfilter@lists.netfilter.org =2D----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In general it is not so hard to apply and activate the H.323 patch. you have to 1) download iptables, download POM(patch-o-matic) for the proper version of= =20 iptables i think 2) have the kernel source of course=20 3) untar&unzip everything (I have done this in /usr/src) than 4) I do a backup of my compiled kernel directory and than start making all = the=20 rest to avoid recompiling everything=20 5) apply the patches (there is info how to do this in POM itself and you do= n't=20 need to apply patches that you won't use and know - try first only the H.32= 3=20 patch) 6) reconfigure your kernel and enable H.323 (networking options =3D> ip=20 netfilter configuration) 7) (re)make your new kernel 8) change into iptables dir and make "make KERNEL_DIR=3D ... " path to your= =20 kernel=20 make install 9) enable your kernel (ex. make install, make modules_install - change lilo= ,=20 grub, boot, make initrd or anything you use) IMPORTANT TIP 10) Be sure to have a rescue floppy or entry in the bootloader for the old= =20 kernel to be able to boot your old configuration in case of failure =2D -------------- If it's just you staying behind a firewall and useing netmeeting and you h= ave=20 rights to manage the firewall, you can forward the ports (1720 and few=20 others) to your windows machine (google tells you how) best regards and good luck On Saturday 19 July 2003 09:08, gold gold wrote: > Hello everybody, > > > > I've already asked this question before, but here it is again: > > > > How do I enable my masqueraded Windows machine to use MSN's audio/video > conversation? I've been told to load the "H323" module and do some > "patch-o-matic stuff" (??), but I don't really know alot about these > stuff... could someone please give me detailed step-by-step instructions = on > how to do that? I would really appreciate this. Thanks a lot. > > _________________________________________________________________ > The new MSN 8: smart spam protection and 2 months FREE* > http://join.msn.com/?page=3Dfeatures/junkmail =2D --=20 //---------------------- || || Emanoil Kotsev =20 || || tel. 0043 1 9253175 || \\--- penguin friendly-- =2D----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE/Gl0xMdng4VCsE9oRAsEiAJ0d3yV9oMkvPW681sqQrZfX6pcSbwCgvFfQ KEw1uuBn/Y4HSb3AY5A5+kQ=3D =3DI0tH =2D----END PGP SIGNATURE----- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Morrison, Trevor (Trevor)" Subject: h323 Date: Mon, 11 Aug 2003 11:50:22 -0600 Sender: netfilter-admin@lists.netfilter.org Message-ID: <2C8B3976EDADFD41950F8C628F3E255A06B56626@co9510avexu2.global.avaya.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C36031.097F00FD" Return-path: content-class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------_=_NextPart_001_01C36031.097F00FD Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi, I have a RH 9.0 box running iptables-1.2.8 and a 2.4.20 kernel with the = h323 patch applied and recompiled. My network looks like this: dhcp from ISP Win 2000 box <--------------------------->RH 9.0 = Box<---------------------->Internet 192.168.1.0/24 NAT 12.207.X.X/32 I have searched the archives back to September of last year trying to = find what rules I need to apply to my iptables to allow h323 traffic = through my NAT'd box. I am now more confused then before because the = threads mentioned something about a gatekeeper that I need to run on a = NAT box? What I am looking for is what are the rules that I need to put into my = filter file and what other programs or procedures do I need to add to = that I have the full features and functionality of Microsoft's Net = Meeting from my Win 2k box. =20 Thanks in Advance and sorry for bring this subject up again but I could = not find the information in the previous threads. Trevor Morrison ------_=_NextPart_001_01C36031.097F00FD Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable h323

Hi,

I have a RH 9.0 box running = iptables-1.2.8 and a 2.4.20 kernel with the h323 patch applied and = recompiled.  My network looks like this:

        =         =         =             dhcp from ISP
Win 2000 box = <--------------------------->RH 9.0 = Box<---------------------->Internet
192.168.1.0/24  =         =         =         = NAT       12.207.X.X/32


I have searched the archives back to = September of last year trying to find what rules I need to apply to my = iptables to allow h323 traffic through my NAT'd box.  I am now more = confused then before because the threads mentioned something about a = gatekeeper that I need to run on a NAT box?

What I am looking for is what are the = rules that I need to put into my filter file and what other programs or = procedures do I need to add to that I have the full features and = functionality of Microsoft's Net Meeting from my Win 2k box.  =

Thanks in Advance and sorry for bring = this subject up again but I could not find the information in the = previous threads.

Trevor Morrison

------_=_NextPart_001_01C36031.097F00FD-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: DALive Editor Subject: Re: h323 Date: Mon, 11 Aug 2003 16:46:51 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <3F3800BB.6060603@flashmail.com> References: <2C8B3976EDADFD41950F8C628F3E255A06B56626@co9510avexu2.global.avaya.com> Reply-To: dalive@flashmail.com Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="------------010006080508090109040506" Return-path: In-Reply-To: <2C8B3976EDADFD41950F8C628F3E255A06B56626@co9510avexu2.global.avaya.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org Cc: "Morrison, Trevor (Trevor)" This is a multi-part message in MIME format. --------------010006080508090109040506 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Hello to this mailinglist, I'd also really like an awnser to the question bellow about H323, you have no idea how long I've toiled unsuccessfully. What is this about a patch? And I've read a little about the gatekeeper, could someone cluse me in further? Thanks alot - I'd given up hope Morrison, Trevor (Trevor) wrote: > Hi, > > I have a RH 9.0 box running iptables-1.2.8 and a 2.4.20 kernel with > the h323 patch applied and recompiled. My network looks like this: > > dhcp from ISP > Win 2000 box <--------------------------->RH 9.0 > Box<---------------------->Internet > 192.168.1.0/24 NAT 12.207.X.X/32 > > > I have searched the archives back to September of last year trying to > find what rules I need to apply to my iptables to allow h323 traffic > through my NAT'd box. I am now more confused then before because the > threads mentioned something about a gatekeeper that I need to run on a > NAT box? > > What I am looking for is what are the rules that I need to put into my > filter file and what other programs or procedures do I need to add to > that I have the full features and functionality of Microsoft's Net > Meeting from my Win 2k box. > > Thanks in Advance and sorry for bring this subject up again but I > could not find the information in the previous threads. > > Trevor Morrison > --------------010006080508090109040506 Content-Type: text/html; charset=us-ascii Content-Transfer-Encoding: 7bit Hello to this mailinglist,

I'd also really like an awnser to the question bellow about H323, you have no idea how long I've toiled unsuccessfully. What is this about a patch? And I've read a little about the gatekeeper, could someone cluse me in further?

Thanks alot - I'd given up hope


Morrison, Trevor (Trevor) wrote:
h323

Hi,

I have a RH 9.0 box running iptables-1.2.8 and a 2.4.20 kernel with the h323 patch applied and recompiled.  My network looks like this:

                                    dhcp from ISP
Win 2000 box <--------------------------->RH 9.0 Box<---------------------->Internet
192.168.1.0/24                          NAT       12.207.X.X/32


I have searched the archives back to September of last year trying to find what rules I need to apply to my iptables to allow h323 traffic through my NAT'd box.  I am now more confused then before because the threads mentioned something about a gatekeeper that I need to run on a NAT box?

What I am looking for is what are the rules that I need to put into my filter file and what other programs or procedures do I need to add to that I have the full features and functionality of Microsoft's Net Meeting from my Win 2k box. 

Thanks in Advance and sorry for bring this subject up again but I could not find the information in the previous threads.

Trevor Morrison

--------------010006080508090109040506-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "George Vieira" Subject: RE: h323 Date: Tue, 12 Aug 2003 20:48:34 +1000 Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <3F3800BB.6060603@flashmail.com> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0008_01C36113.19090400" Return-path: In-Reply-To: <3F3800BB.6060603@flashmail.com> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: dalive@flashmail.com, netfilter@lists.netfilter.org Cc: "Morrison, Trevor (Trevor)" This is a multi-part message in MIME format. ------=_NextPart_000_0008_01C36113.19090400 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Just use the H323 patch in p-o-m... I use it and it works fine for me.. I don't know what this gatekeeper is.. but it's not needed if you can successfully patch in the pom module. -----Original Message----- From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of DALive Editor Sent: Tuesday, August 12, 2003 6:47 AM To: netfilter@lists.netfilter.org Cc: Morrison, Trevor (Trevor) Subject: Re: h323 Hello to this mailinglist, I'd also really like an awnser to the question bellow about H323, you have no idea how long I've toiled unsuccessfully. What is this about a patch? And I've read a little about the gatekeeper, could someone cluse me in further? Thanks alot - I'd given up hope Morrison, Trevor (Trevor) wrote: Hi, I have a RH 9.0 box running iptables-1.2.8 and a 2.4.20 kernel with the h323 patch applied and recompiled. My network looks like this: dhcp from ISP Win 2000 box <--------------------------->RH 9.0 Box<---------------------->Internet 192.168.1.0/24 NAT 12.207.X.X/32 I have searched the archives back to September of last year trying to find what rules I need to apply to my iptables to allow h323 traffic through my NAT'd box. I am now more confused then before because the threads mentioned something about a gatekeeper that I need to run on a NAT box? What I am looking for is what are the rules that I need to put into my filter file and what other programs or procedures do I need to add to that I have the full features and functionality of Microsoft's Net Meeting from my Win 2k box. Thanks in Advance and sorry for bring this subject up again but I could not find the information in the previous threads. Trevor Morrison ------=_NextPart_000_0008_01C36113.19090400 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable
Just=20 use the H323 patch in p-o-m... I use it and it works fine for=20 me..
I=20 don't know what this gatekeeper is.. but it's not needed if you can = successfully=20 patch in the pom module.
 
-----Original Message-----
From:=20 netfilter-admin@lists.netfilter.org=20 [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of DALive=20 Editor
Sent: Tuesday, August 12, 2003 6:47 AM
To:=20 netfilter@lists.netfilter.org
Cc: Morrison, Trevor=20 (Trevor)
Subject: Re: h323

Hello to this=20 mailinglist,

I'd also really like an awnser to the question = bellow about=20 H323, you have no idea how long I've toiled unsuccessfully. What is this = about a=20 patch? And I've read a little about the gatekeeper, could someone cluse = me in=20 further?

Thanks alot - I'd given up hope


Morrison, = Trevor=20 (Trevor) wrote:

Hi,

I have a RH 9.0 box running = iptables-1.2.8 and a=20 2.4.20 kernel with the h323 patch applied and recompiled.  My = network=20 looks like this:

       =20        =20        =20             dhcp from ISP
Win=20 2000 box <--------------------------->RH 9.0=20 Box<---------------------->Internet
192.168.1.0/24  =        =20        =20        =20 NAT       12.207.X.X/32


I have searched the archives back to = September of=20 last year trying to find what rules I need to apply to my iptables to = allow=20 h323 traffic through my NAT'd box.  I am now more confused then = before=20 because the threads mentioned something about a gatekeeper that I need = to run=20 on a NAT box?

What I am looking for is what are the = rules that I=20 need to put into my filter file and what other programs or procedures = do I=20 need to add to that I have the full features and functionality of = Microsoft's=20 Net Meeting from my Win 2k box. 

Thanks in Advance and sorry for bring = this subject=20 up again but I could not find the information in the previous=20 threads.

Trevor Morrison=20

------=_NextPart_000_0008_01C36113.19090400-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Sundaram Ramasamy" Subject: Re: h323 Date: Fri, 15 Aug 2003 09:34:53 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <004b01c36332$04c83490$8c01a8c0@RSUNDARAM> References: Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0048_01C36310.7B704E10" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: George Vieira , dalive@flashmail.com, netfilter@lists.netfilter.org Cc: "Morrison, Trevor (Trevor)" This is a multi-part message in MIME format. ------=_NextPart_000_0048_01C36310.7B704E10 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Can you post your iptables rules for this? ----- Original Message -----=20 From: George Vieira=20 To: dalive@flashmail.com ; netfilter@lists.netfilter.org=20 Cc: Morrison, Trevor (Trevor)=20 Sent: Tuesday, August 12, 2003 6:48 AM Subject: RE: h323 Just use the H323 patch in p-o-m... I use it and it works fine for = me.. I don't know what this gatekeeper is.. but it's not needed if you can = successfully patch in the pom module. -----Original Message----- From: netfilter-admin@lists.netfilter.org = [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of DALive Editor Sent: Tuesday, August 12, 2003 6:47 AM To: netfilter@lists.netfilter.org Cc: Morrison, Trevor (Trevor) Subject: Re: h323 Hello to this mailinglist,=20 I'd also really like an awnser to the question bellow about H323, you = have no idea how long I've toiled unsuccessfully. What is this about a = patch? And I've read a little about the gatekeeper, could someone cluse = me in further?=20 Thanks alot - I'd given up hope Morrison, Trevor (Trevor) wrote: Hi,=20 I have a RH 9.0 box running iptables-1.2.8 and a 2.4.20 kernel with = the h323 patch applied and recompiled. My network looks like this: dhcp from ISP=20 Win 2000 box <--------------------------->RH 9.0 = Box<---------------------->Internet=20 192.168.1.0/24 NAT 12.207.X.X/32=20 I have searched the archives back to September of last year trying = to find what rules I need to apply to my iptables to allow h323 traffic = through my NAT'd box. I am now more confused then before because the = threads mentioned something about a gatekeeper that I need to run on a = NAT box? What I am looking for is what are the rules that I need to put into = my filter file and what other programs or procedures do I need to add to = that I have the full features and functionality of Microsoft's Net = Meeting from my Win 2k box. =20 Thanks in Advance and sorry for bring this subject up again but I = could not find the information in the previous threads. Trevor Morrison=20 ------=_NextPart_000_0048_01C36310.7B704E10 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Can you post your iptables rules for=20 this?
----- Original Message -----
From:=20 George Vieira =
To: dalive@flashmail.com ; netfilter@lists.netfilter.o= rg=20
Sent: Tuesday, August 12, 2003 = 6:48=20 AM
Subject: RE: h323

Just=20 use the H323 patch in p-o-m... I use it and it works fine for=20 me..
I=20 don't know what this gatekeeper is.. but it's not needed if you can=20 successfully patch in the pom module.
 
-----Original Message-----
From: netfilter-admin@lists= .netfilter.org=20 [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of DALive = Editor
Sent: Tuesday, August 12, 2003 6:47 AM
To: = netfilter@lists.netfilter.o= rg
Cc:=20 Morrison, Trevor (Trevor)
Subject: Re:=20 h323

Hello to this mailinglist,

I'd also = really=20 like an awnser to the question bellow about H323, you have no idea how = long=20 I've toiled unsuccessfully. What is this about a patch? And I've read = a little=20 about the gatekeeper, could someone cluse me in further? =

Thanks alot -=20 I'd given up hope


Morrison, Trevor (Trevor) wrote:

Hi,

I have a RH 9.0 box running = iptables-1.2.8 and a=20 2.4.20 kernel with the h323 patch applied and recompiled.  My = network=20 looks like this:

       =20        =20        =20             dhcp from ISP
Win 2000 box <--------------------------->RH 9.0=20 Box<---------------------->Internet
192.168.1.0/24  =        =20        =20        =20 NAT       12.207.X.X/32 =


I have searched the archives back to = September of=20 last year trying to find what rules I need to apply to my iptables = to allow=20 h323 traffic through my NAT'd box.  I am now more confused then = before=20 because the threads mentioned something about a gatekeeper that I = need to=20 run on a NAT box?

What I am looking for is what are the = rules that=20 I need to put into my filter file and what other programs or = procedures do I=20 need to add to that I have the full features and functionality of=20 Microsoft's Net Meeting from my Win 2k box. 

Thanks in Advance and sorry for bring = this=20 subject up again but I could not find the information in the = previous=20 threads.

Trevor Morrison=20

------=_NextPart_000_0048_01C36310.7B704E10-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Scott van Looy Subject: Re: h323 Date: Fri, 15 Aug 2003 15:36:14 +0100 (BST) Sender: netfilter-admin@lists.netfilter.org Message-ID: References: <004b01c36332$04c83490$8c01a8c0@RSUNDARAM> Mime-Version: 1.0 Return-path: In-Reply-To: <004b01c36332$04c83490$8c01a8c0@RSUNDARAM> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: TEXT/PLAIN; charset="us-ascii" Content-Transfer-Encoding: 7bit Cc: netfilter@lists.netfilter.org You'll need to be happy building your own custom redhat kernel - install from source patch-o-matic, adding the h323 patch recompile kernel, then boot into kernel install from source iptables then make sure your modules are loaded /sbin/modprobe -k ip_nat_h323 /sbin/modprobe -k ip_conntrack_h323 open ports 1503 and 1720 (389 and 522 if you want to use ils) and it should just work! Today Sundaram Ramasamy did spake thusly: > Can you post your iptables rules for this? > ----- Original Message ----- > From: George Vieira > To: dalive@flashmail.com ; netfilter@lists.netfilter.org > Cc: Morrison, Trevor (Trevor) > Sent: Tuesday, August 12, 2003 6:48 AM > Subject: RE: h323 > > > Just use the H323 patch in p-o-m... I use it and it works fine for me.. > I don't know what this gatekeeper is.. but it's not needed if you can successfully patch in the pom module. > > -----Original Message----- > From: netfilter-admin@lists.netfilter.org [mailto:netfilter-admin@lists.netfilter.org]On Behalf Of DALive Editor > Sent: Tuesday, August 12, 2003 6:47 AM > To: netfilter@lists.netfilter.org > Cc: Morrison, Trevor (Trevor) > Subject: Re: h323 > > > Hello to this mailinglist, > > I'd also really like an awnser to the question bellow about H323, you have no idea how long I've toiled unsuccessfully. What is this about a patch? And I've read a little about the gatekeeper, could someone cluse me in further? > > Thanks alot - I'd given up hope > > > Morrison, Trevor (Trevor) wrote: > > Hi, > > I have a RH 9.0 box running iptables-1.2.8 and a 2.4.20 kernel with the h323 patch applied and recompiled. My network looks like this: > > dhcp from ISP > Win 2000 box <--------------------------->RH 9.0 Box<---------------------->Internet > 192.168.1.0/24 NAT 12.207.X.X/32 > > > > I have searched the archives back to September of last year trying to find what rules I need to apply to my iptables to allow h323 traffic through my NAT'd box. I am now more confused then before because the threads mentioned something about a gatekeeper that I need to run on a NAT box? > > What I am looking for is what are the rules that I need to put into my filter file and what other programs or procedures do I need to add to that I have the full features and functionality of Microsoft's Net Meeting from my Win 2k box. > > Thanks in Advance and sorry for bring this subject up again but I could not find the information in the previous threads. > > Trevor Morrison > -- Scott van Looy - email:me@ethosuk.org.uk | web:www.ethosuk.org.uk PGP Fingerprint: 7180 5543 C6C4 747B 7E74 802C 7CF9 E526 44D9 D4A7 ------------------------------------------- |/// /// /// /// WIDE LOAD /// /// /// ///| ------------------------------------------- "Irrigation of the land with sewater desalinated by fusion power is ancient. It's called 'rain'." -- Michael McClary, in alt.fusion From mboxrd@z Thu Jan 1 00:00:00 1970 From: "George Vieira" Subject: RE: h323 Date: Mon, 18 Aug 2003 07:51:33 +1000 Sender: netfilter-admin@lists.netfilter.org Message-ID: <09B04A55822EFF4DA48D2E0BB2941D4A15C0F6@wardrive.citadelcomputer.com.au> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C36509.B99CF24C" Return-path: content-class: urn:content-classes:message Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------_=_NextPart_001_01C36509.B99CF24C Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable insmod ip_nat_h323 insmod ip_conntrack_h323 =20 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 389 = -j DNAT --to 192.168.0.1 # H323 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 522 = -j DNAT --to 192.168.0.1 # H323 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1503 = -j DNAT --to 192.168.0.1 # H323 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1720 = -j DNAT --to 192.168.0.1 # H323 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1731 = -j DNAT --to 192.168.0.1 # H323 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 8080 = -j DNAT --to 192.168.0.1 # H323 $IPTABLES -t nat -A PREROUTING -i $EXTDEV -p tcp --dport 1469 = -j DNAT --to 192.168.0.1 # H323aud =20 =20 =20 Thanks, =20 ____________________________________________ George Vieira Citadel Computer Systems Pty Ltd Systems Manager georgev AT = citadelcomputer DOT com DOT au=20 Citadel Computer Systems Pty Ltd Phone : +61 2 9955 2644 HelpDesk: +61 2 9955 2698 = http://www.citadelcomputer.com.au =20 =20 -----Original Message----- From: Sundaram Ramasamy [mailto:sun@percipia.com] Sent: Friday, August 15, 2003 11:35 PM To: George Vieira; dalive@flashmail.com; netfilter@lists.netfilter.org Cc: Morrison, Trevor (Trevor) Subject: Re: h323 Can you post your iptables rules for this? ----- Original Message -----=20 From: George Vieira =20 To: dalive@flashmail.com ; netfilter@lists.netfilter.org=20 Cc: Morrison, Trevor (Trevor) =20 Sent: Tuesday, August 12, 2003 6:48 AM Subject: RE: h323 Just use the H323 patch in p-o-m... I use it and it works fine for me.. I don't know what this gatekeeper is.. but it's not needed if you can = successfully patch in the pom module. ------_=_NextPart_001_01C36509.B99CF24C Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
        = insmod=20 ip_nat_h323
        = insmod=20 ip_conntrack_h323
 
        $IPTABLES -t nat -A = PREROUTING=20 -i $EXTDEV -p tcp --dport 389    -j DNAT --to 192.168.0.1    &nbs= p;   =20 # H323
        $IPTABLES -t nat -A = PREROUTING -i $EXTDEV -p tcp --dport 522    -j DNAT --to = 192.168.0.1    &nbs= p;   =20 # H323
        $IPTABLES -t nat -A = PREROUTING -i $EXTDEV -p tcp --dport 1503   -j DNAT --to 192.168.0.1    &nbs= p;   =20 # H323
        $IPTABLES -t nat -A = PREROUTING -i $EXTDEV -p tcp --dport 1720   -j DNAT --to 192.168.0.1    &nbs= p;   =20 # H323
        $IPTABLES -t nat -A = PREROUTING -i $EXTDEV -p tcp --dport 1731   -j DNAT --to 192.168.0.1    &nbs= p;   =20 # H323
        $IPTABLES -t nat -A = PREROUTING -i $EXTDEV -p tcp --dport 8080   -j DNAT --to 192.168.0.1    &nbs= p;   =20 # H323
        $IPTABLES -t nat -A = PREROUTING -i $EXTDEV -p tcp --dport 1469   -j DNAT --to 192.168.0.1    &nbs= p;   =20 # H323aud
 
 
 

Thanks,

 
____________________________________________George=20 Vieira
Citadel=20 Computer Systems Pty Ltd Systems=20 Manager georgev AT=20 citadelcomputer DOT com DOT au
Citadel Computer Systems Pty Ltd
Phone : +61 2 9955=20 2644 HelpDesk: +61 2 9955=20 2698 http://www.citadelcomputer.co= m.au
 
 
-----Original Message-----
From: Sundaram Ramasamy=20 [mailto:sun@percipia.com]
Sent: Friday, August 15, 2003 11:35=20 PM
To: George Vieira; dalive@flashmail.com;=20 netfilter@lists.netfilter.org
Cc: Morrison, Trevor=20 (Trevor)
Subject: Re: h323

Can you post your iptables rules for=20 this?
----- Original Message -----
From:=20 George Vieira =
To: dalive@flashmail.com ; netfilter@lists.netfilter.o= rg=20
Sent: Tuesday, August 12, 2003 = 6:48=20 AM
Subject: RE: h323

Just=20 use the H323 patch in p-o-m... I use it and it works fine for=20 me..
I=20 don't know what this gatekeeper is.. but it's not needed if you can=20 successfully patch in the pom=20 module.
------_=_NextPart_001_01C36509.B99CF24C-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Jeffrey J. Karrels" Subject: H323 Date: Mon, 5 Apr 2004 11:10:35 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Hello, I am trying to get Netmeeting/Remote Desktop Sharing to work. I have 2.4.20-30.9 kernel and am running iptables-1.2.9. I have patched the kernel with the only the H323 patch. I opened up the 1720 and 1503 ports. I get the following message in my syslog when I try to open up an connection from the outside going in: H.323_NAT: partial packet 0/6 in 0/0 I have seen this in the mailing list a couple of times, I was wondering if anyone knew anything about it? Any suggestions? Am I missing something? Thank you -Jeff From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael =?ISO-8859-1?Q?Fern=E1ndez?= "M." Subject: h323 Date: Fri, 21 Jul 2006 09:00:23 -0400 Message-ID: <1153486823.16671.74.camel@debian.sernam2k.cl> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Hi.... Someone have h323 modules (netfilter) working on Debian Sarge (Kernel 2.4.27)... i need these modules but i`m not sure about how to patch the kernel... There is a good document that explain the process? Thanks a lot!!!! Michael.-