Re: Hiding internal ip from the internet.

paddy <[email protected]> Wed, 27 Oct 2004 19:54:24 +0100
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Message-ID <[email protected]>
On Wed, Oct 27, 2004 at 02:12:10PM -0400, Dan Gordon wrote:
> Hello list,
> Just installed my first smoothwall,  I'm impressed.
> One thing I was wondering is when I do a scan at several of the web 
> sites on the net that check for open ports and stuff some of them 
> report that they can see my internal ip address as well as my external 
> ip address.  

I would imagine they got this from your browser. I take it your LAN is
'off-net'. man tcpdump.

> There are two reported closed ports showing also 80 and 
> 113.

80 is http. 113 is ident.

> Is this normal behavior ?  

here's a smoothwall2 at random, 
from the outside:

  # nmap (a smoothie)
  
  Starting nmap 3.50 ( http://www.insecure.org/nmap/ ) at 2004-10-27 19:39 BST
  Interesting ports on XXX
  (The 1652 ports scanned but not shown below are in state: filtered)
  PORT     STATE  SERVICE
  113/tcp  closed auth
  222/tcp  open   rsh-spx
  441/tcp  open   decvms-sysmgt
  
  Nmap run completed -- 1 IP address (1 host up) scanned in 119.850 seconds
  
I've taken out the ports we forward.
from the inside:
  
  # nmap sw
  
  Starting nmap 3.55 ( http://www.insecure.org/nmap/ ) at 2004-10-27 19:42 BST
  Interesting ports on sw 
  (The 1657 ports scanned but not shown below are in state: closed)
  PORT    STATE SERVICE
  81/tcp  open  hosts2-ns
  222/tcp open  rsh-spx
  441/tcp open  decvms-sysmgt
  
  Nmap run completed -- 1 IP address (1 host up) scanned in 2.706 seconds

81 & 441 are http(s) for the admin interface
222 is sshd
The 113 is an ident proxy or fake or something, I forget (yes, its normal).
are you perhaps forwarding 80 ?  perhaps it is the web-proxy, I don't have
that on right now.
  
> Also can the smoothwall be monitored or configured locally ?

locally ? try pointing a browser at http://xx.xx.xx.xx:81/
where xx.xx.xx.xx is the internal ip address for the smoothwall.

Regards,
Paddy
-- 
Perl 6 will give you the big knob. -- Larry Wall
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall