LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-27-2006, 03:51 AM   #1
RedPlanet
LQ Newbie
 
Registered: Jan 2006
Posts: 2

Rep: Reputation: 0
Linux webproxy/firewall and WAN connection


Hi, here's a wild one i'm hoping someone will advise me on.
Small company here.
The IT guy had installed Linux for our webproxy and firewall. Also put up an antenna on the roof of the building and has another Linux computer connected to it, handling the routing for the WAN.
Now this is just a small time operation here, basically he was directing (via the WAN) the web to his own home and to the owners home (local isp's are unreliable old school dialup) so they could VPN from home.

Sounds good except rumors circulate that that isn't all he's done. In fact there are rumors that half his friends are leeching web from this company via his WAN links which he has setup here and there around the county.

So i wonder is there a way to discover what is really going on here. Providing i have the root login for the proxy/firewall, where do i start?
 
Old 01-28-2006, 07:49 PM   #2
Sir_Limpalot
LQ Newbie
 
Registered: Jan 2006
Location: Norway
Distribution: Debian
Posts: 18

Rep: Reputation: 0
When you say leeching web, do you mean they have their own servers running over your line or that they are using your line to surf the web?
Anyway you can use iptables to log the traffic that's going over the wan-link, don't know the interface, but something like

iptables -I FORWARD -i eth1 -j LOG

would log all traffic coming in on the eth1 interface for forwarding and all those links (with ip's) would show up in /var/log/messages (on debian at least)....
If there are more ip-addresses showing up than there are legal connections to the line that would be a clue.
You could then try blocking them off (by mac-address) one by one and see who complained about loosing access.

Good luck
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Multiple WAN interfaces (FreeBSD Firewall) mxk *BSD 4 03-17-2005 11:21 AM
FreeS/Wan Vs. OpenS/Wan Vs. StrongS/Wan bkankur Linux - Security 1 03-01-2005 09:27 AM
Failed WAN connection Buckyjunior Linux - Networking 2 10-10-2004 10:47 AM
LAN to WAN Connection MNF Mandrake Firewall? aaziz Linux - Networking 0 02-16-2004 02:25 AM
Using nmap to scan my firewall through WAN proxy slooper Linux - Security 5 12-08-2003 10:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration