Welcome to the most active Linux Forum on the web.
Go Back > Forums > Linux Forums > Linux - Networking
User Name
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.


  Search this Thread
Old 07-19-2004, 10:25 AM   #1
LQ Guru
Registered: Aug 2003
Distribution: CentOS, OS X
Posts: 5,131

Rep: Reputation: Disabled
nat/masquerade, connection tracking's the story cut short: I have set up a small home network, access the net from my pc through a firewalling machine, and have been unable to use things like irc DCC, instant messaging sends (things the kind of msn, icq etc.) and so on. I have to use masquerading/nat to get the net working on my pc, and mostly it does - the only things that do not work are those file sends I mentioned above (receiving ok)

then I heard about iptables (which I use for firewalling) modules called ip_conntrack_irc and ip_nat_irc that should solve my problem - I modprobed them, restarted my irc client and tried....worked like magic. now what's the problem, you ask - it's that this won't work anymore!

so, I'd like to get an explanation. it's been a week or two when this worked, for one evening. I was running my machines normally, modprobed the modules mentioned above, restarted irc software and DCC send worked...I also think instant messaging sends and so on would have worked. anyway, it worked nicely, until I shut my own pc in the evening..a few days passed as I didn't need my machine, and when I started it up no dcc send worked, no instant messaging send worked, nothing like that..I double-checked that I had the ip_conntrack_irc and ip_nat_irc modules loaded, normal net worked fine, DCC works and so on (but...Gtk-Gnutella doesn't? I don't use it, but won't work. I tested with it.)

so what has happened? I haven't changed my firewall configuration, it's untouched. people do get a message when I try to send them something over some other protocol than http, but when they accept the transfer, it never starts. it's like I wouldn't have the connection tracking working, since my firewall should let "known" connections through..but if the modules are loaded, why wouldn't it work?

thanks for any info..also, if somebody could tell why DC (dcgui-qt) works but Gnutella doesn't, I'd be pleased. not that I'd need them that badly, but it's nice to know and this irc/instant messaging stuff...that's what I need, because emails are pure pain when sending a bit bigger files like archives to people I need to send them to because of my work. emails just don't do the thing..

oh, one more thing - if I send something from the firewalling machine itself, and no nat/masquerading is done (right?), everything works perfectly. what killed my working conntrack?
Old 07-19-2004, 10:19 PM   #2
Registered: Aug 2003
Location: Oz
Distribution: Gentoo - Debian
Posts: 202

Rep: Reputation: 30
what do you get when you do

iptables -L

Old 07-20-2004, 04:22 AM   #3
LQ Guru
Registered: Aug 2003
Distribution: CentOS, OS X
Posts: 5,131

Original Poster
Rep: Reputation: Disabled
somehow big (well..not actually that big) list of my firewall rules..including forwarding and so on. the default policies are set to DROP, and I've checked that NAT works with forwarding (otherwise my internet wouldn't work)...I can post the output here if you wish, but I'm pretty sure it's ok.

the odd thing is, that even if I set up a firewall with default policies set to ACCEPT and the only rules made for forwarding and NAT to work, it still won't is the problem with NAT? but how could it be..if the connection tracking modules are loaded ok?

EDIT: one more thing. I checked this on irc with one of my friends - when I send a file, and my friend gets the notice of it, he _does_ get the ip address that my isp gives to me, and _not_ the internal network address. so this proves, I think, that NAT does work but why don't I still get it ok? could there be a possibility that the address is NATed when I send the question for file send, but when the answer comes back, it isn't translated and sticks to my firewall rather than continuing to my own pc?

Last edited by b0uncer; 07-20-2004 at 04:25 AM.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
disable connection tracking lmqhfx Fedora - Installation 1 09-17-2005 10:31 PM
Help with connection tracking vishamr2000 Linux - Security 1 05-27-2005 09:37 AM
Help with connection tracking!! vishamr2000 Linux - Security 1 05-27-2005 04:47 AM
iptables - true nat AND masquerade rebuke Linux - Security 3 11-11-2003 02:02 PM
Connection tracking for Active FTP paradoxlight Linux - Networking 1 03-25-2003 03:18 AM > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:21 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration