OK
here is the entire script I execute called routerSetup.sh
<File>
/sbin/iptables --flush
/sbin/iptables --table nat --flush
/sbin/iptables --delete-chain
/sbin/iptables --table nat --delete-chain
/sbin/iptables -A FORWARD -i ppp0 -o eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A FORWARD -i eth1 -o ppp0 -m state ! --state INVALID -j ACCEPT
/sbin/iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE
/sbin/iptables -P INPUT DROP
/sbin/iptables -P FORWARD DROP
/sbin/iptables -P OUTPUT DROP
/sbin/iptables -A INPUT -i lo -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A OUTPUT -o ppp0 -m state ! --state INVALID -j ACCEPT
echo 1 > /proc/sys/net/ipv4/ip_forward
</File>
Here is what I recieve from "iptables -L"
<Output>
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
</Output>
As far as assigning the DNS to my windows clients, I can't do it. The ppp0(DSL modem to eth0) uses PPPoE, so my DNS server IP is assigned to me dynamically.
I also can no longer ping my windows client 192.168.0.2, nor can I ping my router from my windows box. However, I can ping the Internet from my router. Here is that output
<Ping internet>
PING
www.google.akadns.net (216.239.39.99) from 65.42.228.59 : 56(84) bytes of data.
64 bytes from 216.239.39.99: icmp_seq=1 ttl=49 time=44.3 ms
64 bytes from 216.239.39.99: icmp_seq=2 ttl=49 time=45.2 ms
</Ping>
<Ping client>
PING 192.168.0.2 (192.168.0.2) from 192.168.0.1 : 56(84) bytes of data.
ping: sendmsg: Operation not permitted
ping: sendmsg: Operation not permitted
</Ping>
Thanks for all the help thus far, I really appreciate it.
Todd