* port forwarding with one interface to trace traffic? @ 2004-01-21 15:45 Rasca 2004-01-21 16:16 ` Caracal - G. Hostettler 2004-01-21 22:07 ` Antony Stone 0 siblings, 2 replies; 7+ messages in thread From: Rasca @ 2004-01-21 15:45 UTC (permalink / raw) To: netfilter Hi IP-gurus, I want to setup a specific port forwarding to trace the ip traffic between a macos9 and a hp net printer to debug a spooler problem. I thought the port forwarding feature of linux/iptables would be nice to do that. But until now I wasn't able to get it running ;-( May be some one can help here. The setup is quite simple. * one class C net (192.168.10.0) * a linux box with one interface (eth0), kernel 2.4.24 and iptables 1.2.9 (192.168.10.156 * macos9 machine with 9.2.x (192.168.10...) * HP laser printer with network interface (192.168.10.9) I want to configure the Mac to print to the linux box. The linux box should do port forwarding to the hp printer. So I can use "ethereal" or what ever to dump the traffic. Because it's not a firewall all chains have as default "accept". I added the following rule (which seems not to be enough, cause the printing freezes): iptables -t nat -A PREROUTING -p tcp --dport 515 \ -d 192.168.10.156/32 -j DNAT --to-dest 192.168.10.9:515 Any ideas? thx + cu rasca -- _______________________________________________________________ | Triad Berlin Projektgesellschaft mbH | http://www.triad.de/ | ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: port forwarding with one interface to trace traffic? 2004-01-21 15:45 port forwarding with one interface to trace traffic? Rasca @ 2004-01-21 16:16 ` Caracal - G. Hostettler 2004-01-21 16:46 ` Rasca 2004-01-21 22:07 ` Antony Stone 1 sibling, 1 reply; 7+ messages in thread From: Caracal - G. Hostettler @ 2004-01-21 16:16 UTC (permalink / raw) To: Rasca; +Cc: netfilter list Just one silly question: Do you have a "1" in /proc/sys/net/ipv4/ip_forward ? If a zero, nothing will go through. BTW, I never used such a config with only on interface. I am *not* a guru, but having a mask of /32 instead of /24 seems strange to me. What is the mask on your printer and on your Mc ? GH ----- Original Message ----- From: "Rasca" <rasca-ml@triad.de> To: <netfilter@lists.netfilter.org> Sent: Wednesday, January 21, 2004 4:45 PM Subject: port forwarding with one interface to trace traffic? > Hi IP-gurus, > > I want to setup a specific port forwarding to trace the > ip traffic between a macos9 and a hp net printer to debug > a spooler problem. > > I thought the port forwarding feature of linux/iptables > would be nice to do that. But until now I wasn't able > to get it running ;-( > > May be some one can help here. The setup is quite simple. > > * one class C net (192.168.10.0) > * a linux box with one interface (eth0), kernel 2.4.24 > and iptables 1.2.9 (192.168.10.156 > > * macos9 machine with 9.2.x (192.168.10...) > > * HP laser printer with network interface (192.168.10.9) > > I want to configure the Mac to print to the linux box. > The linux box should do port forwarding to the hp printer. > So I can use "ethereal" or what ever to dump the traffic. > > Because it's not a firewall all chains have as default > "accept". > > I added the following rule (which seems not to be enough, > cause the printing freezes): > > iptables -t nat -A PREROUTING -p tcp --dport 515 \ > -d 192.168.10.156/32 -j DNAT --to-dest 192.168.10.9:515 > > Any ideas? > > thx + cu > rasca > > > -- > _______________________________________________________________ > | Triad Berlin Projektgesellschaft mbH | http://www.triad.de/ | > > ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: port forwarding with one interface to trace traffic? 2004-01-21 16:16 ` Caracal - G. Hostettler @ 2004-01-21 16:46 ` Rasca 0 siblings, 0 replies; 7+ messages in thread From: Rasca @ 2004-01-21 16:46 UTC (permalink / raw) To: Caracal - G. Hostettler; +Cc: netfilter list Hi, Caracal - G. Hostettler schrieb: > Just one silly question: > > Do you have a "1" in /proc/sys/net/ipv4/ip_forward ? > If a zero, nothing will go through. yep, of course it's setup to "1". > BTW, I never used such a config with only on interface. may be it's not possible, or the setup for only one interface is more complicated!? > I am *not* a guru, but having a mask of /32 instead of /24 seems strange to > me. as long as I know it means no subnet, just the IP for the host.. > What is the mask on your printer and on your Mc ? class C (255.255.255.0) cu rasca >> >>I want to setup a specific port forwarding to trace the >>ip traffic between a macos9 and a hp net printer to debug >>a spooler problem. >> >>I thought the port forwarding feature of linux/iptables >>would be nice to do that. But until now I wasn't able >>to get it running ;-( >> >>May be some one can help here. The setup is quite simple. >> >>* one class C net (192.168.10.0) >>* a linux box with one interface (eth0), kernel 2.4.24 >> and iptables 1.2.9 (192.168.10.156 >> >>* macos9 machine with 9.2.x (192.168.10...) >> >>* HP laser printer with network interface (192.168.10.9) >> >>I want to configure the Mac to print to the linux box. >>The linux box should do port forwarding to the hp printer. >>So I can use "ethereal" or what ever to dump the traffic. >> >>Because it's not a firewall all chains have as default >>"accept". >> >>I added the following rule (which seems not to be enough, >>cause the printing freezes): >> >>iptables -t nat -A PREROUTING -p tcp --dport 515 \ >>-d 192.168.10.156/32 -j DNAT --to-dest 192.168.10.9:515 >> >>Any ideas? >> >>thx + cu >> rasca >> >> >>-- >>_______________________________________________________________ >>| Triad Berlin Projektgesellschaft mbH | http://www.triad.de/ | >> >> > > -- _______________________________________________________________ | Triad Berlin Projektgesellschaft mbH | http://www.triad.de/ | ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: port forwarding with one interface to trace traffic? 2004-01-21 15:45 port forwarding with one interface to trace traffic? Rasca 2004-01-21 16:16 ` Caracal - G. Hostettler @ 2004-01-21 22:07 ` Antony Stone 2004-01-22 13:16 ` Jeffrey Laramie 1 sibling, 1 reply; 7+ messages in thread From: Antony Stone @ 2004-01-21 22:07 UTC (permalink / raw) To: netfilter On Wednesday 21 January 2004 3:45 pm, Rasca wrote: > Hi IP-gurus, > > May be some one can help here. The setup is quite simple. > > * one class C net (192.168.10.0) > * a linux box with one interface (eth0), kernel 2.4.24 > and iptables 1.2.9 (192.168.10.156 > > * macos9 machine with 9.2.x (192.168.10...) > > * HP laser printer with network interface (192.168.10.9) > > I want to configure the Mac to print to the linux box. > The linux box should do port forwarding to the hp printer. > So I can use "ethereal" or what ever to dump the traffic. Your problem with this is a simple networking one, nothing specific to netfilter. Here's a description of where the packets go in your setup: 1. Mac sends to 192.168.10.156 2. Netfilter translates destination address and packet goes to printer at 192.168.10.9 3. Printer replies to Mac (because source address remains unchanged). Therefore the Mac is unhappy and upset, because it sent to 192.168.10.156, and got a reply from 192.168.109.9. TCP doesn't allow that, therefore printing doesn't work. Your solutions? 1. Add second interface to the firewall, and make sure the client and server are on opposite sides of it, so that packets in both directions have to go through the netfilter machine (which will then perform the reverse NAT in the opposite direction) 2. Perform SNAT as well as DNAT on the netfilter system so that the Mac think it's printing to the netfilter box (which does DNAT so the packets get sent to the printer, but also does SNAT so the printer replies back to netfilter, and reverse NAT can then successfully send the replies back to the Mac) 3. Connect a hub (not a switch) to the printer's ethernet cable (or to the Mac's ethernet cable), and plug the Linux machine running ethereal into the hub, so you can sniff the packets off the wire without any NAT. My recommendation would be for option 3, because it makes the least change to your existing network setup and ensures you can investigate the problem without doing something which may affect packet routing etc (which could turn out to be the cause you are looking for). Regards, Antony. -- This email is intended for the use of the individual addressee(s) named above and may contain information that is confidential, privileged or unsuitable for overly sensitive persons with low self-esteem, no sense of humour, or irrational religious beliefs. If you have received this email in error, you are required to shred it immediately, add some nutmeg, three egg whites and a dessertspoonful of caster sugar. Whisk until soft peaks form, then place in a warm oven for 40 minutes. Remove promptly and let stand for 2 hours before adding some decorative kiwi fruit and cream. Then notify me immediately by return email and eat the original message. Please reply to the list; please don't CC me. ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: port forwarding with one interface to trace traffic? 2004-01-21 22:07 ` Antony Stone @ 2004-01-22 13:16 ` Jeffrey Laramie 2004-01-22 13:36 ` Rasca 2004-01-22 13:39 ` PPTP and GRE Jan Kaastrup 0 siblings, 2 replies; 7+ messages in thread From: Jeffrey Laramie @ 2004-01-22 13:16 UTC (permalink / raw) To: netfilter > >3. Connect a hub (not a switch) to the printer's ethernet cable (or to the >Mac's ethernet cable), and plug the Linux machine running ethereal into the >hub, so you can sniff the packets off the wire without any NAT. > > Hi Antony This is dangerously OT, but what's the difference? I always thought that the difference between a switch and a hub was simply a matter of internal plumbing that affected how the pipes were connected and had no effect on the actual tcp/ip connections. I've used them interchangeably and haven't seen a difference. Maybe someone has a link that could educate me more better! :-) Jeff ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: port forwarding with one interface to trace traffic? 2004-01-22 13:16 ` Jeffrey Laramie @ 2004-01-22 13:36 ` Rasca 2004-01-22 13:39 ` PPTP and GRE Jan Kaastrup 1 sibling, 0 replies; 7+ messages in thread From: Rasca @ 2004-01-22 13:36 UTC (permalink / raw) To: Jeffrey Laramie; +Cc: netfilter Hi, Jeffrey Laramie schrieb: > >> >> 3. Connect a hub (not a switch) to the printer's ethernet cable (or to >> the Mac's ethernet cable), and plug the Linux machine running ethereal >> into the hub, so you can sniff the packets off the wire without any NAT. >> >> > > This is dangerously OT, but what's the difference? I always thought that > the difference between a switch and a hub was simply a matter of > internal plumbing that affected how the pipes were connected and had no > effect on the actual tcp/ip connections. I've used them interchangeably > and haven't seen a difference. Maybe someone has a link that could > educate me more better! :-) A "hub" broadcasts all packets to all port. And yes - that was the way I choosed, cause it's more simple to setup (I found an old hub..) and it's working. thx to Antony. cu rasca -- _______________________________________________________________ | Triad Berlin Projektgesellschaft mbH | http://www.triad.de/ | ^ permalink raw reply [flat|nested] 7+ messages in thread
* PPTP and GRE 2004-01-22 13:16 ` Jeffrey Laramie 2004-01-22 13:36 ` Rasca @ 2004-01-22 13:39 ` Jan Kaastrup 1 sibling, 0 replies; 7+ messages in thread From: Jan Kaastrup @ 2004-01-22 13:39 UTC (permalink / raw) To: netfilter Hi list I am running poptop on kernel 2.4.23. I need the patch, that makes it possible for GRE to do NAT I remember i have done it before, but not how :) In my ip_conntrack the gre protocol stands as "UNKNOWN", and remember i have seen it says "gre". Any help will be appriciated Thanks a lot. ^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2004-01-22 13:39 UTC | newest] Thread overview: 7+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2004-01-21 15:45 port forwarding with one interface to trace traffic? Rasca 2004-01-21 16:16 ` Caracal - G. Hostettler 2004-01-21 16:46 ` Rasca 2004-01-21 22:07 ` Antony Stone 2004-01-22 13:16 ` Jeffrey Laramie 2004-01-22 13:36 ` Rasca 2004-01-22 13:39 ` PPTP and GRE Jan Kaastrup
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox