Hi been having some trouble getting ym rules correct was hoping someone could chip in.
so here is the setup:
Tunis: (win7)
eth0: 192.168.5.9 FROM
(Firewall off)
Alexandria: (CENTOS6)
eth1: 192.168.5.1 VIA
eth0: 10.14.137.91
ebcdemo-AD1 (WIN2k8R2)
eth0: 10.14.136.1 VIA
mascara: (WIn7)
eth0: 10.14.137.129 TO
I have admin/root access to all machines.
Current State:
tracert/ping - Tunis> Alexandria : SUCCESS
tracert/ping - Tunis> Ebcdemo-AD1 VIA alexandria : FAIL
tracert/ping - Mascara>Alexandria VIA Ebcdemo-AD1 : SUCCESS
tracert/ping - Mascara>Tunis VIA EBCdemo-AD1-alexandria: FAIL
tracert - mascara>tunis : FAIL - gets to 10.14.136.1 (ebcdemo-AD1 and gets lost)
So with that information i hope that sets a good foundation to figure this out.
There seems to be two issues. One is forwarding across alexandria (centos) and the other forwarding from 10.14.136.1 to 10.14.137.91 to then send across the subnet gap to 192.168.5.1.
I understand there is some windows involved and technically out of this websites remit, but please forgive me! maybe we can atleast get the traffic moving from Tunis via alexandria to ebcdemo-AD1.
below i have pasted the current iptables rules i have... (p.s i am aware they are veryvery open but i my network does not need to be secure as it's a lab.)
Code:
[roo@alexandria Mozilla]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- 192.168.5.9 anywhere
ACCEPT all -- 192.168.5.0/26 anywhere
ACCEPT all -- 10.14.136.0/24 anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
EDIT: i figured it may be worth mentioning the IP route setup incase there is an error there:
Code:
[roo@alexandria Mozilla]#ip route
192.168.5.0/26 dev eth1 proto kernel scope link src 192.168.5.1
10.14.136.0/24 dev eth0 proto kernel scope link src 10.14.137.91
169.254.0.0/16 dev eth1 scope link metric 1002 #i believe this entry is from a past ipclash
169.254.0.0/16 dev eth0 scope link metric 1003 #that i have since sorted?
So to sum up.
How can i get traffic (lets say a ping) moving from Tunis to mascara and vice versa?