LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-20-2003, 07:34 PM   #1
cdeorla
LQ Newbie
 
Registered: Sep 2003
Posts: 5

Rep: Reputation: 0
SuSEfirewall2


Ok, so I've tried everything I can think of to make this work - no luck

All I want to do is pass port 25 traffic coming from the internet through our firewall (private address) over to the DMZ (private address) where a postfix box resides, then forward off to another DMZ (private address) or back to the firewall where it will get routed to an internal server...

So therefore, the flow would be

Internet ---> firewall ----> My DMZ postfix 1 -----> firewall (postfix)
|
| (or based on destination)
|
------> Other DMZ postfix 2


firewall = int 172.23.1.76
ext 216.200.200.200
dmz 10.10.100.2


My DMZ = eth0 10.10.100.200
eth1 10.10.10.200
eth2 172.23.1.199

Other DMZ = eth0 10.10.100.150
eth1 10.10.10.20

I know it sound like a riggamarole, but I have my reasons....

Someone must have done this - I'll even settle for traffic passing from f/w to my DMZ as a starting point ????

Send me a working config if you have one - thx in advance...

Help and thanks in advance !?!
 
Old 09-20-2003, 09:26 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Send me a working config if you have one
Add log target rules for any "decision", check the logs and adjust your rules accordingly. Then post the output and the script you're using.
 
Old 09-21-2003, 05:51 AM   #3
cdeorla
LQ Newbie
 
Registered: Sep 2003
Posts: 5

Original Poster
Rep: Reputation: 0
new (related ?) problem

Alrighty... here's the deal...

I followed one document that gave me a little insight into what I needed to try and that worked - sort of.

The new problem of the day is now:

When a connection comes in from the internet on port 25, it is reverse-masq forwarded to the DMZ, however it only allows one connection at a time. The other connections that come through go into a SYN_SENT state and then eventually a TIME_WAIT state and then either time out or as each connection is cleared the next one connects. For SMTP traffic this means that typically the connection is dropped and then retried later. For example, I sent two simultaneous emails from outside to myself from different sources - one went through (slowly I might add), the other one took almost 15 minutes to retry but finally made it through.

While one connection is made the others sit and wait or are dropped (connection failure - not dropped by the firewall)

Any ideas ? We process about 1000 emails a day....

Cd
 
Old 09-21-2003, 04:12 PM   #4
Z8002
LQ Newbie
 
Registered: Sep 2003
Location: Lancashire
Distribution: SuSe 9.0
Posts: 12

Rep: Reputation: 0
You may find the thread that I started to be of some help.

FW_FORWARD_MASQ="194.217.242.164,192.168.0.2,tcp,25 "

works for me, from Demon Internet.

194.217.242.164 is where Demon send out smtp,

192.168.0.2. is my machine with the local smtp server

But see the caveats in my thread.

HTH

Nick.
 
Old 09-21-2003, 07:09 PM   #5
cdeorla
LQ Newbie
 
Registered: Sep 2003
Posts: 5

Original Poster
Rep: Reputation: 0
My boneheadedness

I got it to work....

My routing was apparently the problem....

Things would apparently connect or at least pass thru, but it would never connect properly (SYN_RCVD) or (TIME_WAIT)...I read another article with similarities that stated routing was his problem and bingo !

What I will do, once I have a good solid running config, is post it here with my list of "Gotcha's" for all the other poor souls living on twinkies and coffee to make this work...

To add more complexities into the mix, now I'm working on Squid in conjunction to all this !!!

I need a life...

Thanks for your responses

Cd
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba and SuSEFirewall2 apachedude SUSE / openSUSE 42 08-03-2005 07:53 PM
SuSEFirewall2 problem sucram2g Linux - Networking 0 06-19-2005 06:48 AM
SuseFirewall2 XaViaR SUSE / openSUSE 4 06-02-2005 10:40 PM
SuseFirewall2 question brent1a Linux - Networking 2 05-23-2004 03:31 PM
susefirewall2 gazza Linux - Newbie 2 04-05-2004 01:22 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration