LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-18-2004, 08:40 PM   #1
bryan1138
LQ Newbie
 
Registered: Jan 2004
Location: Louisville, KY
Posts: 10

Rep: Reputation: 0
Internal network not getting back in...


I just setup my NAT with webmin using the Linux Firewall. For some reason I cannot browse to my web servers or mail server. Everyone else is able to though. It feels like I am leaving out one small setting.

And one more thing I cannot get the IP_Forward to stay on 1. After reboot it is back to 0 again. I cannot figure out how to save that setting.

Help me oh great Linux Gurus, your my only hope!
 
Old 01-19-2004, 01:22 AM   #2
je_fro
Member
 
Registered: Nov 2002
Location: /texas/austin/home/desk
Distribution: Gentoo
Posts: 341

Rep: Reputation: 30
BAH!
Gui tools...fsck you up every time.
I suggest you read up on iptables and make your own script, starting with a base script from here:
http://iptables-script.dk/
 
Old 01-19-2004, 07:39 AM   #3
bryan1138
LQ Newbie
 
Registered: Jan 2004
Location: Louisville, KY
Posts: 10

Original Poster
Rep: Reputation: 0
Thanks I am being such a !! I just got so close with Webmin. I am being lazy and did not want to script it. Everything works great except I cannot get into my webserver while behind my router.
 
Old 01-19-2004, 07:40 AM   #4
bryan1138
LQ Newbie
 
Registered: Jan 2004
Location: Louisville, KY
Posts: 10

Original Poster
Rep: Reputation: 0
Sweet script generator!!! Thanks
 
Old 01-19-2004, 12:45 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Generally traffic is not allow by firewalls to go "out then back in", i.e. you cannot have internal private addresses connect to your outside public IPs. This is by design.

Instead, use the internal IP of your server for local clients to connect to.
 
Old 01-19-2004, 12:53 PM   #6
bryan1138
LQ Newbie
 
Registered: Jan 2004
Location: Louisville, KY
Posts: 10

Original Poster
Rep: Reputation: 0
So how does a cheap Linksys cable router handle the external to internal NAT? Before I dove headfirst into iptables, I had a Linksys doing all of my routing. I was able to do forwarding and be able to browse "back in" with no problem. Would this mean that a Linksys router is better than a Linux router? I hope not.


Thank You

Last edited by bryan1138; 01-19-2004 at 01:07 PM.
 
Old 01-19-2004, 03:52 PM   #7
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
No, it means a Linksys is less secure because it allows the outside IP to "talk to itself". Linksys did it out of convenience for people that don't understand how networking is supposed to work. Whatever iptables script you're using handles the situation more correctly.

You have two interfaces on your Linux router, yes? Two IPs, one outside, one inside, yes? So point your LAN clients to the IP of the inside interface, that's how it's supposed to work. If DNS is a problem, you can override it for your LAN clients by putting the Fully Qualified Domain Name in /etc/hosts and associate it with the internal IP. Note: This has to be done on the client machines, not the server. Also if you're using Windows, the hosts file will be found in various places depending on what version of Windows you use.
 
Old 01-19-2004, 04:25 PM   #8
bryan1138
LQ Newbie
 
Registered: Jan 2004
Location: Louisville, KY
Posts: 10

Original Poster
Rep: Reputation: 0
Thanks again for the clairification. I will edit the host file. Good Idea.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Routing on my internal network. Milkman00 Linux - Networking 11 09-02-2005 02:30 PM
Iptables-- internal network HopelessLinuxNewbie Linux - Security 3 07-27-2005 08:49 PM
sendmail for internal network and network config questions RedHat123 Linux - Networking 0 04-06-2005 03:15 PM
internal network problem Gilion Linux - Networking 1 11-10-2003 01:01 PM
Bridge or internal network? What should i do? kokolisso Linux - Networking 3 01-13-2002 10:25 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration