LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-21-2005, 05:29 AM   #1
sikkalgopal
Member
 
Registered: Aug 2004
Location: india
Distribution: Mandrakes,Redhats,Debians.Suses and FreeBSD
Posts: 52

Rep: Reputation: 15
smoothwall configuration


Hi all,

In our test lab i have two networks 10.0.0.0 hosts start from 10.0.0.101,102 etc and another 192.168.0.0 hosts start from 192.168.0.101,102 etc. In between i hav smoothwall box having two nic configured 10.0.0.3 as green (localnet) and 192.168.0.1 as red (anothernet) . I have backup linux server in 192 network i want to backup from some of the machines in 10 network.How can i set the forwarding rule
here,i tried many possible thing but cant able to ping from 10 network to 192 network.

From smoothwall eitherside i can able to pink.

pls help
thnks
 
Old 06-21-2005, 06:03 AM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Have you looked at the log file pages in the interface to see if it records the ping?
 
Old 06-21-2005, 07:13 AM   #3
sikkalgopal
Member
 
Registered: Aug 2004
Location: india
Distribution: Mandrakes,Redhats,Debians.Suses and FreeBSD
Posts: 52

Original Poster
Rep: Reputation: 15
Hi

I dont find any problems with nic,still i can able to ping from the box to eitherside of the network,also from the 10.0.0.network to the 192.168.0.1 (red interface of smoothwall),beyond i get request timed out.

but from 192.168 network if i ping 10.0.0.3 (green interface of smoothwall),i get destination port unreachable.

problem seems to be in the forwarding rule,i tired up after using many combination
thnks

Last edited by sikkalgopal; 06-21-2005 at 07:16 AM.
 
Old 06-21-2005, 07:26 AM   #4
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Smoothwall isn't designed to allow pings from Red (internet) interface directly to the Internal (green) interface.. No firewall should allow that, ever.

Things that need to be pinged live in the DMZ zone.

Check the Snort logs and see if it is blocking the pings from Green to 192.168. network.
 
Old 06-21-2005, 07:34 AM   #5
sikkalgopal
Member
 
Registered: Aug 2004
Location: india
Distribution: Mandrakes,Redhats,Debians.Suses and FreeBSD
Posts: 52

Original Poster
Rep: Reputation: 15
Hi

thnks your reply, checked both alert and portscan.log both are 0 bytes no entry registered

is any way of making forward rule from 10.0 network to 192.168 ?

pls advice
thnks
 
Old 06-21-2005, 08:00 AM   #6
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Only by ip number and protocol to a single pc..

Smoothwall isn't this kind of firewall, doing routing functions.
The rule sets are quite complicated and from many parts.
Were you looking for specific features from it?
 
Old 06-21-2005, 08:50 AM   #7
sikkalgopal
Member
 
Registered: Aug 2004
Location: india
Distribution: Mandrakes,Redhats,Debians.Suses and FreeBSD
Posts: 52

Original Poster
Rep: Reputation: 15
Hi

thnks, ya we have specific backup application and wants to check across the firewall, and also with the specific port. from the smoothwall docs i understand that communication takes place between networks across the firewall must exist in the orange and red network and not in the green network. is it right? if so i have to add one more nic and one more network with hosts.
It seems logically work right?

Put it in single way all hosts from one network can backup to a server available in another network over a specified port,also restoring from server to the host over the same port.

bye

Last edited by sikkalgopal; 06-21-2005 at 09:01 AM.
 
Old 06-21-2005, 09:02 AM   #8
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
That's correct..

The Orange is for DMZ.. No new communications into the Green from Orange.
 
Old 06-21-2005, 09:43 AM   #9
sikkalgopal
Member
 
Registered: Aug 2004
Location: india
Distribution: Mandrakes,Redhats,Debians.Suses and FreeBSD
Posts: 52

Original Poster
Rep: Reputation: 15
Hi

things going more complex now,i dont want make more networks,is any firewall suitable for my
condition.

thnks in advance
bye
 
Old 06-21-2005, 04:49 PM   #10
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
You can make one from any Linux distro using the iptables package..

A tutorial with examples is at http://iptables-tutorial.frozentux.n...-tutorial.html
 
Old 06-21-2005, 07:13 PM   #11
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
Not sure if this is going to help
but could you use IP Cop
and set up a vpn or pinholes ( as they call them )
from blue zone to green zone

floppy

edit
just to include this link
http://www.ipcop.org/1.4.0/en/instal...iguration.html
Am I correct in that you want to do what is in point 1.2.1.3
that is communicate from blue to green ?
hope this helps

Last edited by floppywhopper; 06-21-2005 at 07:24 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Configuration Help w/ Smoothwall 2.0 Express mlitos Linux - Security 14 10-21-2004 04:42 PM
Smoothwall Express 2.0 - Configuration problems cgtueno Linux - Networking 2 06-17-2004 08:23 AM
Help with smoothwall scarr Linux - Networking 4 03-26-2003 05:05 PM
Smoothwall 2.0 configuration... PLZHELP~ VIVIDTRUTH Linux - Networking 2 02-28-2003 06:57 PM
smoothwall kafnir Linux - Networking 11 02-26-2003 02:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration