Hello all,
I've two systems on lan.
Let us assume that the one which has modem be sys1 and the second one be sys2.
i've dial up connection to the internet.
Now i'm trying to configure shorewall on my sys1 so that i can access internet from my sys2 also using sys1 as gateway.
......................................
using "netconfig" on both the systems i've set the ip address.
sys1 192.168.0.1
sys2 192.168.0.2
both systems are pinging each other perfectly.
......................................
Its for the first time that i'm trying to configure shorewall so i'm not very much confident with the entries which i made in
****/etc/shorewall/"various files"****
.......................................
Code:
root@bond:~# ifconfig
eth0 Link encap:Ethernet HWaddr 00:A1:B0:10:19:2E
inet addr:192.168.0.1 Bcast:192.168.0.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:50 errors:0 dropped:0 overruns:0 frame:0
TX packets:34 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:4444 (4.3 Kb) TX bytes:3108 (3.0 Kb)
Interrupt:10 Base address:0xcc00
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
ppp0 Link encap:Point-to-Point Protocol
inet addr:61.95.216.58 P-t-P:202.56.24.135 Mask:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:591 errors:0 dropped:0 overruns:0 frame:0
TX packets:669 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:3
RX bytes:258482 (252.4 Kb) TX bytes:87850 (85.7 Kb)
root@bond:~#
Code:
root@bond:~# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
202.56.24.135 0.0.0.0 255.255.255.255 UH 0 0 0 ppp0
192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo
0.0.0.0 202.56.24.135 0.0.0.0 UG 0 0 0 ppp0
root@bond:~#
Entries in /etc/shorewall/interfaces
Code:
##############################################################################
#ZONE INTERFACE BROADCAST OPTIONS
net ppp0 - routefilter,norfc1918,tcpflags
loc eth0 - tcpflags
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
Entries in /etc/shorewall/masq
Code:
#############################################################################
#INTERFACE SUBNET ADDRESS PROTO PORT(S) IPSEC
ppp0 eth0
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE
/etc/shorewall/policy
Code:
###############################################################################
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
loc net ACCEPT
# If you want open access to the Internet from your Firewall
# remove the comment from the following line.
fw net ACCEPT
net all DROP info
# THE FOLLOWING POLICY MUST BE LAST
all all REJECT info
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE
/etc/shorewall/shorewall.conf
Code:
# If left blank, or set to "No" or "no", the option is not enabled.
#
CLAMPMSS=Yes
/etc/shorewall/zones
Code:
#ZONE DISPLAY COMMENTS
net Net Internet
loc Local Local Networks
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE
where am i missing something?????.............b'coz my sys2 can't connect to internet through sys1 as gateway.......
route -n on sys2
Code:
root@bond:~# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo
0.0.0.0 192.168.0.1 0.0.0.0 UG 0 0 0 eth0
root@bond:~#
thanx in adv. to all of u who will be trying to sort out the problem..
regards