* IPT Still Driving Me Nuts
@ 2003-11-02 18:00 David C. Hart
2003-11-02 18:16 ` Tom Eastep
0 siblings, 1 reply; 3+ messages in thread
From: David C. Hart @ 2003-11-02 18:00 UTC (permalink / raw)
To: iptables mailing list
[-- Attachment #1: Type: text/plain, Size: 349 bytes --]
"Nov 2 12:36:45 mail2 kernel: -FW- IN=eth1 OUT=
MAC=00:09:5b:22:29:d1:00:06:25:e4:ed:a3:08:00 SRC=61.172.3.25
DST=192.168.0.31 LEN=530 TOS=0x00 PREC=0x00 TTL=239 ID=21777
PROTO=UDP SPT=32937 DPT=1026 LEN=510"
I have eliminated the virtual internal IP. The message above is still a
mismatch. That IP is on IF eth0 while it shows on eth1.
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: IPT Still Driving Me Nuts
2003-11-02 18:00 IPT Still Driving Me Nuts David C. Hart
@ 2003-11-02 18:16 ` Tom Eastep
[not found] ` <1067797945.18250.8.camel@main.tqmcube.com>
0 siblings, 1 reply; 3+ messages in thread
From: Tom Eastep @ 2003-11-02 18:16 UTC (permalink / raw)
To: David C. Hart; +Cc: iptables mailing list
On Sun, 2003-11-02 at 10:00, David C. Hart wrote:
> "Nov 2 12:36:45 mail2 kernel: -FW- IN=eth1 OUT=
> MAC=00:09:5b:22:29:d1:00:06:25:e4:ed:a3:08:00 SRC=61.172.3.25
> DST=192.168.0.31 LEN=530 TOS=0x00 PREC=0x00 TTL=239 ID=21777
> PROTO=UDP SPT=32937 DPT=1026 LEN=510"
>
> I have eliminated the virtual internal IP. The message above is still a
> mismatch. That IP is on IF eth0 while it shows on eth1.
Are eth0 and eth1 connected to the same Hub/Switch?
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: IPT Still Driving Me Nuts
[not found] ` <1067798390.26406.16.camel@wookie.shorewall.net>
@ 2003-11-02 18:57 ` David C. Hart
0 siblings, 0 replies; 3+ messages in thread
From: David C. Hart @ 2003-11-02 18:57 UTC (permalink / raw)
To: iptables mailing list; +Cc: Tom Eastep
[-- Attachment #1: Type: text/plain, Size: 507 bytes --]
On Sun, 2003-11-02 at 13:39, Tom Eastep wrote:
> Such a setup is pure "security by obscurity" since the firewall can be
> bypassed by hosts on your external subnet. Having both interfaces
> connected to the same HUB/switch also means that either interface can
> answer ARP "who-has" requests for addresses assigned to either
> interface. That's why you see the "wrong" interface accepting input
> traffic.
>
OK. I reconfigured and pulled the plug on eth1 to the router. Let's see
what happens.
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2003-11-02 18:57 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-02 18:00 IPT Still Driving Me Nuts David C. Hart
2003-11-02 18:16 ` Tom Eastep
[not found] ` <1067797945.18250.8.camel@main.tqmcube.com>
[not found] ` <1067798390.26406.16.camel@wookie.shorewall.net>
2003-11-02 18:57 ` David C. Hart
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox