From mboxrd@z Thu Jan 1 00:00:00 1970 From: "WT" Subject: UDP and IPIP forwarding Date: Thu, 5 Dec 2002 20:55:29 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <003601c29c5d$aa821aa0$1a00a8c0@lncwei> Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0033_01C29CA0.A4E69330" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0033_01C29CA0.A4E69330 Content-Type: text/plain; charset="gb2312" Content-Transfer-Encoding: quoted-printable Hi guys, I am trying to set up 2 IPtables based Firewall/NAT with UDP and IPIP = forwarding function as listed below: 1) Forward UDP (port 434) package to an internal host; 2) Forward IPIP package to a host in the same subnet as the Firewall's, = where the outer IP head of the IPIP package has a destination to a = special IP address.=20 Here is an illustration of the scenario: package from 192.168.0.1 to 192.168.0.10 (UDP 434) |=20 v --------------192.168.0.10-----------------=20 10.3.10.10 | forward to 10.3.10.201 v --------------10.3.10.201---------------------------------------- = 10.3.10.13---------------- to 172.3.10.5 (IPIP) = 172.3.10.13 from 10.3.10.201 | = | forward to 172.3.10.5 = v = 172.3.10.5 (get IPIP package and reply to 192.168.0.1) = =20 The IPIP reply from 172.3.10.5 to 192.168.0.1 needs to be forwarded by = 10.3.10.13 to 10.3.10.201. I used IPtable and Linux 8 on 192.168.0.10 and 10.3.10.13 and = encountered both problems: 1) Only one UDP package (the 1st one?) is forwarded to 10.3.10.201, = others are dropped. And once a while (every 12 minutes), there is one = package forwarded. That's it. 2) I can Ping the 10.3.10.201 in the Firewall's subnet, but IPIP package = is not forwarded at all. They are still sent to 192.168.0.1 and = dropped... Can any expert give me some idea what may be wrong? I followed the = instruction of the IPtables. But it just doesn't work well. Please help. Thanks! Wey ------=_NextPart_000_0033_01C29CA0.A4E69330 Content-Type: text/html; charset="gb2312" Content-Transfer-Encoding: quoted-printable
Hi guys,
 
I am trying to set up 2 IPtables = based=20 Firewall/NAT with UDP and IPIP forwarding function as listed = below:
 
1) Forward UDP (port 434) package to an = internal=20 host;
2) Forward IPIP package to a host in the same subnet as the = Firewall's,=20 where the outer IP head of the IPIP package has a destination to a = special IP=20 address.
 
Here is an illustration of the=20 scenario:
 
   package from=20 192.168.0.1
          &nbs= p;      to=20 192.168.0.10 (UDP 434)
          &nbs= p;            = ; |=20
          &nbs= p;            = ;=20 v
--------------192.168.0.10-----------------=20
          &nbs= p;   =20 10.3.10.10
          &nbs= p;            = ;=20 | forward to 10.3.10.201
          &nbs= p;            = ; v
--------------10.3.10.201---------------------------------------= -=20 10.3.10.13----------------
          &nbs= p;            = ;            =  to 172.3.10.5=20 (IPIP)        = 172.3.10.13
          &nbs= p;            = ;            =  from=20 10.3.10.201    =20              = |
          &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;      |=20 forward to 172.3.10.5
          &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;     =20 v
          &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;172.3.10.5=20 (get IPIP package and reply to 192.168.0.1)
          &nbs= p;            = ;            =             &= nbsp;           &n= bsp;           &nb= sp;           &nbs= p;=20
 
The IPIP reply from 172.3.10.5 to = 192.168.0.1=20 needs to be forwarded by 10.3.10.13 to 10.3.10.201.
 
I used IPtable and Linux 8 on = 192.168.0.10 and=20 10.3.10.13 and encountered both problems:
1) Only one UDP package = (the 1st=20 one?) is forwarded to 10.3.10.201, others are dropped. And once a while = (every=20 12 minutes), there is one package forwarded. That's it.
2) I can Ping = the 10.3.10.201 in the Firewall's subnet, but IPIP package is not = forwarded=20 at all. They are still sent to 192.168.0.1 and dropped...
 
Can any expert give me some idea what = may be wrong?=20 I followed the instruction of the IPtables. But it just doesn't work = well.=20 Please help.
 
Thanks!
 
Wey
------=_NextPart_000_0033_01C29CA0.A4E69330-- ____________________________ BN3 Hosted Customer Service Solution, basic service FREE. CRM enable your web site in 5 minutes! http://www.bn3.com