Welcome to the { mindfrost82.com } forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-08-2008, 09:16 PM
David Zelinsky
 
Posts: n/a
ip forwarding woes

I'm trying to set up a firewall/gateway, and I can't seem to get
ip forwarding to work. I'm using linux kernel 2.6.23 with iptables
enabled. Here's what happens.

The firewall machine has two interfaces (both on private networks, for
testing purposes):

IF IP Netmask
eth0 192.168.0.1 255.255.255.0
eth1 10.0.0.1 255.255.255.0

This is the routing table:

Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
10.0.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1

I enable IP forwarding, with 'echo 1 >/proc/sys/net/ipv4/ip_forward'

I have the iptables_* modules loaded (* = forward,nat,mangle,raw).
There are no rules in any of the tables, but all have ACCEPT as the
default policy.

I have two other machines, one at 192.168.0.2 (connected to the same
hub as firewall's eth0) and one at 10.0.0.2 (connected via crossover
to firewall's eth1).

From the firewall, I can ping both the other hosts.
From either host, I can ping the firewall at both 192.160.0.1 and 10.0.0.1.

With this setup, I expect to be able to ping 10.0.0.2 from 192.168.0.2
(and vice versa), with packets routed through the firewall, but it
doesn't work.

What am I overlooking?

I did try putting explicit iptables rules in the FILTER chain of the
forward table, but it didn't make any difference.

Any suggestions would be much appreciated.

--
David Zelinsky

Reply With Quote
  #2 (permalink)  
Old 03-08-2008, 10:18 PM
David Zelinsky
 
Posts: n/a
Re: ip forwarding woes

Never mind, I found my mistake. The routing table of one of the hosts
was not exactly as described below, and was causing return packets to be
lost. I made the configuration actually agree with what I described and
now it works. Sorry to bother people.

David Zelinsky wrote:
> I'm trying to set up a firewall/gateway, and I can't seem to get
> ip forwarding to work. I'm using linux kernel 2.6.23 with iptables
> enabled. Here's what happens.
>
> The firewall machine has two interfaces (both on private networks, for
> testing purposes):
>
> IF IP Netmask
> eth0 192.168.0.1 255.255.255.0
> eth1 10.0.0.1 255.255.255.0
>
> This is the routing table:
>
> Destination Gateway Genmask Flags Metric Ref Use Iface
> 192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
> 10.0.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
>
> I enable IP forwarding, with 'echo 1 >/proc/sys/net/ipv4/ip_forward'
>
> I have the iptables_* modules loaded (* = forward,nat,mangle,raw).
> There are no rules in any of the tables, but all have ACCEPT as the
> default policy.
>
> I have two other machines, one at 192.168.0.2 (connected to the same
> hub as firewall's eth0) and one at 10.0.0.2 (connected via crossover
> to firewall's eth1).
>
> From the firewall, I can ping both the other hosts.
> From either host, I can ping the firewall at both 192.160.0.1 and 10.0.0.1.
>
> With this setup, I expect to be able to ping 10.0.0.2 from 192.168.0.2
> (and vice versa), with packets routed through the firewall, but it
> doesn't work.
>
> What am I overlooking?
>
> I did try putting explicit iptables rules in the FILTER chain of the
> forward table, but it didn't make any difference.
>
> Any suggestions would be much appreciated.
>

Reply With Quote
  #3 (permalink)  
Old 04-15-2008, 05:30 PM
Ilario
 
Posts: n/a
Re: ip forwarding woes

Could you write down your configuration? It's exactly the problem I'm
trying to solve.. thanks a lot!
Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:38 AM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
Loans | Car Loans | Credit Card Consolidation | Credit Report | Equity



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114