LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-06-2002, 03:41 PM   #1
willix
LQ Newbie
 
Registered: Aug 2002
Distribution: Red Hat 7.3 Valhalla
Posts: 2

Rep: Reputation: 0
linux gateway/firewall with MASQUERADE


Hi all--
I'm pretty new to Linux, so bear with me please! I am trying to set up my Red Hat 7.3 box to be a firewall/gateway for an internal subnet (really only one Windows 2000 machine in the network). I have read several tutorials on firewall software and IP Masquerade and it seems that my best options would be to use Iptables for the firewall and Masquerading since my connection to the Internet is dchp (cable modem). I have set up two NICS and built a pretty decent firewall that won't allow much of anything.

My problem is this..
No matter what I do I can't get the Windows machine to talk to the linux gateway machine. I get no LED lights on the second NIC. Here is the summary of the configuration:

*both NICs are verified to be in working order

eth0 =>dhcp from cable modem
eth1 =>static assigned IP 192.168.1.1
IPforwarding is set to true (1)
rules exist in Iptables such that:
all chains drop everything by default
iptables --table nat --append POSTROUTING -o eth0 -j MASQUERADE
iptables -A FORWARD -i eth1 -j ACCEPT

my routing table looks like this:
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
208.180.146.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo
0.0.0.0 208.180.146.1 0.0.0.0 UG 0 0 0 eth0

I can ping the eth1 NIC at 192.168.1.1
If I ping to 192.168.1.2 (the windows box static IP) it gives me destination host unreachable.

running tcpdump listening on eth1 shows no packets when I ping 192.168.1.1, but shows packets when I try to ping the subnet machine past that point (192.168.1.2) tcp dump listening on eth1 shows no packets when I boot the windows pc's network service. I thought for sure it was a firewall rule problem for the Windows box (boot pc maybe?) but since there were no packets traversing eth1 from the subnet, I can rule that out right??

The Windows box gets:
IP=192.168.1.2
gateway is eth1 in linux box=192.168.1.1
dns is my isp dns server
netmask=255.255.255.0

I thought that maybe it was the firewall blocking packets, so I turned it to accept all packets, but still had the same problem. No ping to the subnet, no link lights on the second NIC, and the Windows box thinks the network cable is unplugged when I start networking.

Does anyone have any suggestions? I've gone through 4 or 5 tutorials on iptables/masquerading/networking with 2 NICS, and tried a few other rule configurations, but pretty much nothing I tried is any different. The windows box just won't find the network. I have been told that even without forwarding and Masq. running I should be able to ping the Windows box from the Linux gateway.

I sure appreciate any help, it is a real pain running a software firewall on that windows machine. Norton Personal Firewall is killing me with all the question pop-ups it asks me all the time!

Thanks,
Will B.
 
Old 08-06-2002, 04:19 PM   #2
chaste
LQ Newbie
 
Registered: Aug 2002
Posts: 16

Rep: Reputation: 0
Hi Will,

I can't help, but just so that you don't feel so alone I'm in the same situation!

If you check out my other posts I've had some great help from a few guys and it may help your problem, even if I haven't quite sorted my own problems out!

I'll be monitoring this thread as well!

-Chris
 
Old 08-06-2002, 05:37 PM   #3
willix
LQ Newbie
 
Registered: Aug 2002
Distribution: Red Hat 7.3 Valhalla
Posts: 2

Original Poster
Rep: Reputation: 0
Chris-
Thanks. I'll dig through your posts and hopefully between them and what I've already tried I can find the solution.

I appreciate it.
Will
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
routing/gateway/masquerade help wanted -=dionis=- Linux - Networking 4 06-25-2005 07:17 AM
Using Linux as a firewall/gateway Dovid Linux - Networking 4 04-21-2005 09:13 PM
Linux gateway/firewall problem dal-san Linux - Networking 3 10-31-2003 03:53 AM
Linux as firewall / gateway + using ADSL Gianni Linux - Security 3 07-22-2003 11:05 AM
DirectPlay, Linux Gateway, Firewall, oh my Hegemon Linux - General 2 03-03-2003 01:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration