LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-18-2002, 09:18 PM   #1
sarin
Member
 
Registered: May 2001
Location: India, Kerala, Thrissur
Distribution: FC 7-10
Posts: 354
Blog Entries: 2

Rep: Reputation: 34
How to make Transparent gateway?


Hi,
Sorry, I am half asleep now.Don't know what exactly I am going to write. Yesterday whole night we where trying to setup a firewall. I was using iptables for the first time Somehow got it working with nat table. But now I have this problem. When I log on to other m/c outside the firewall it says I am from firewall and not from actual m/c. We have another firewall in our campus going past which does not cause such problems. ( If I am from 127.1.2.3, on the other m/c it will still show me to be from 127.1.2.3 and not from firewall). I think they use ipchains. Can some one tell me where to read about this kind of stuff for iptables?.

Thanks,
--Sarin
 
Old 07-18-2002, 11:35 PM   #2
sudheermt
LQ Newbie
 
Registered: Jul 2002
Posts: 11

Rep: Reputation: 0
I suppose you are using NAT , Network Address Translation,
when any machine, behind your firewall communicates,
IP address is rewritten with firewall machine. so it looks all communication is done by your firewall machine.

instead of NAT try IP forwarding.

(I am using IPChains, it was easier to configure.)

Sud's
 
Old 07-19-2002, 06:16 AM   #3
Mik
Senior Member
 
Registered: Dec 2001
Location: The Netherlands
Distribution: Ubuntu
Posts: 1,316

Rep: Reputation: 47
What exactly are you trying to do? Do the machines behind the firewall have a public ip or a private ip? If they have a private ip then you will have to use nat like you are doing. And in that case it's not possible to show the real ip to the outside world.
If you have public ip's then you will have to set up your routing tables properly to get things to pass through.
After that you should set up iptables with a good rule set to block unwanted traffic.
 
Old 07-19-2002, 07:11 AM   #4
sarin
Member
 
Registered: May 2001
Location: India, Kerala, Thrissur
Distribution: FC 7-10
Posts: 354

Original Poster
Blog Entries: 2

Rep: Reputation: 34
We have public ips which can be seen only with in campus. The main gateway do not allow them to go out. ( BW restriction or something ). So from dept if they go out to campus it is fine.
The main reason is, our dhcp clients get reply from other servers and get wrong ips. Also ppl spoof ips and mount our nfs file system. So we don't want the ips used inside to enter through firewall.
The other firewall works with out any routing. I don't know how they do it. ( They gave some command like
arp -h ether -Ds ip pub ). I want something like that. No one should even know what I have done ( No routing changes etc ). But we should be see the network as of now and should be able to block unwanted pkts from comming in.
Sorry for this long reply. But I don't know how clear it is.
--Sarin.
 
Old 07-19-2002, 08:33 AM   #5
Mik
Senior Member
 
Registered: Dec 2001
Location: The Netherlands
Distribution: Ubuntu
Posts: 1,316

Rep: Reputation: 47
Well here is an extract from the man page of arp:
Code:
NOTE: As of kernel 2.2.0 it is no  longer  possible
to  set  an  ARP  entry for an entire subnet. Linux
instead does  automagic  proxy  arp  when  a  route
exists   and  it  is  forwarding.  See  arp(7)  for
details.
You really should add a route instead of just modifying your arp table like that.
You should really be securing your system by writing a decent ruleset for your firewall. Instead of being afraid of modifying your routing tables because you don't want people to know how your traffic gets routed.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
transparent proxy that automaticly configure a client gateway myheart Linux - Networking 2 01-19-2005 07:44 PM
How do you make a KDE desktop transparent ? Yoshimura Mandriva 15 08-10-2004 08:29 AM
Make my taskbar transparent? carlgulliver100 Linux - Software 4 04-16-2004 02:46 AM
make transparent windows? iLLuSionZ Linux - Newbie 5 11-08-2003 03:47 AM
how u make the menu transparent crosslin Linux - General 2 06-04-2003 04:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration