Linux Netfilter discussions
 help / color / mirror / Atom feed
* IPT Still Driving Me Nuts
@ 2003-11-02 18:00 David C. Hart
  2003-11-02 18:16 ` Tom Eastep
  0 siblings, 1 reply; 3+ messages in thread
From: David C. Hart @ 2003-11-02 18:00 UTC (permalink / raw)
  To: iptables mailing list

[-- Attachment #1: Type: text/plain, Size: 349 bytes --]

"Nov  2 12:36:45 mail2 kernel:  -FW-  IN=eth1 OUT=
MAC=00:09:5b:22:29:d1:00:06:25:e4:ed:a3:08:00 SRC=61.172.3.25
DST=192.168.0.31 LEN=530 TOS=0x00 PREC=0x00 TTL=239 ID=21777 
PROTO=UDP SPT=32937 DPT=1026 LEN=510"

I have eliminated the virtual internal IP. The message above is still a
mismatch. That IP is on IF eth0 while it shows on eth1.

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: IPT Still Driving Me Nuts
  2003-11-02 18:00 IPT Still Driving Me Nuts David C. Hart
@ 2003-11-02 18:16 ` Tom Eastep
       [not found]   ` <1067797945.18250.8.camel@main.tqmcube.com>
  0 siblings, 1 reply; 3+ messages in thread
From: Tom Eastep @ 2003-11-02 18:16 UTC (permalink / raw)
  To: David C. Hart; +Cc: iptables mailing list

On Sun, 2003-11-02 at 10:00, David C. Hart wrote:
> "Nov  2 12:36:45 mail2 kernel:  -FW-  IN=eth1 OUT=
> MAC=00:09:5b:22:29:d1:00:06:25:e4:ed:a3:08:00 SRC=61.172.3.25
> DST=192.168.0.31 LEN=530 TOS=0x00 PREC=0x00 TTL=239 ID=21777 
> PROTO=UDP SPT=32937 DPT=1026 LEN=510"
> 
> I have eliminated the virtual internal IP. The message above is still a
> mismatch. That IP is on IF eth0 while it shows on eth1.

Are eth0 and eth1 connected to the same Hub/Switch?

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep@shorewall.net




^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: IPT Still Driving Me Nuts
       [not found]     ` <1067798390.26406.16.camel@wookie.shorewall.net>
@ 2003-11-02 18:57       ` David C. Hart
  0 siblings, 0 replies; 3+ messages in thread
From: David C. Hart @ 2003-11-02 18:57 UTC (permalink / raw)
  To: iptables mailing list; +Cc: Tom Eastep

[-- Attachment #1: Type: text/plain, Size: 507 bytes --]

On Sun, 2003-11-02 at 13:39, Tom Eastep wrote:

> Such a setup is pure "security by obscurity" since the firewall can be
> bypassed by hosts on your external subnet. Having both interfaces
> connected to the same HUB/switch also means that either interface can
> answer ARP "who-has" requests for addresses assigned to either
> interface. That's why you see the "wrong" interface accepting input
> traffic.
> 
OK. I reconfigured and pulled the plug on eth1 to the router. Let's see
what happens.

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-11-02 18:57 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-02 18:00 IPT Still Driving Me Nuts David C. Hart
2003-11-02 18:16 ` Tom Eastep
     [not found]   ` <1067797945.18250.8.camel@main.tqmcube.com>
     [not found]     ` <1067798390.26406.16.camel@wookie.shorewall.net>
2003-11-02 18:57       ` David C. Hart

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox