Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Steve Comfort <steve@4Dllc.com>
To: netfilter <netfilter@lists.netfilter.org>
Subject: Problem with ssh
Date: Wed, 25 Aug 2004 14:26:56 +0200	[thread overview]
Message-ID: <412C8590.8030900@4Dllc.com> (raw)

Hi all,

First off, a feeble attempt at diagramming my setup :

192.168.200.x   eth -> eth  Embedded Linux Wireless  ppp -> ppp Embedded 
Linux Access Point eth0 -> 192.168.1.x

The two Embedded Linux Wireless boxes are actually what I am working on. 
The second one in the list above is configured as a bridge, and doesn't 
currently have any firewalling (because I haven't figured out whether I 
need ebtables or iptables, but that's another story).

The client side wireless box (on the left) has the following rule in it :

$IPTABLES -A bad_tcp_packets -i $INET_IFACE -s 192.168.200.0/16 -j DROP

Here INET_IFACE = ppp0.

If I have this rule in place, I am unable to ssh from a box on the 
192.168.200.x network to one on the 192.168.1.x network.

As I read the above, packets entering the ppp interface on the wireless 
client, with a source address on the .200 sub-net should be dropped. 
Which seems perfectly reasonable. But what I don't understand is why the 
returning ssh packets (which should be sourced on the .1 subnet) are 
being dropped?

Best regards
Steve Comfort




       



             reply	other threads:[~2004-08-25 12:26 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-25 12:26 Steve Comfort [this message]
2004-08-25 12:32 ` Problem with ssh Markus Linden
  -- strict thread matches above, loose matches on Subject: below --
2004-08-25 12:31 Jason Opperisano
2004-08-25 16:55 Hudson Delbert J Contr 61 CS/SCBN

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=412C8590.8030900@4Dllc.com \
    --to=steve@4dllc.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox