Re: firewall: advanced mode

Achim Weber <[email protected]> Mon, 24 Nov 2014 18:35:44 +0100
Newsgroups gmane.comp.security.ipcop.devel
Message-ID <[email protected]>
Hi Michael,

> > remove all those Source Port settings from your firewall rules. As normally
> > the source port is dynamic your firewall rules does not match anymore...
> > 
> What do you mean by removing source ports?
> If I want to port forward foo.bar:25 to secret.foo.bar:25 should there not be
> defined a source port if it is only port 25 I want to forward? If no source
> port is specified it will be any port to foo.bar which is forwarded to
> secret.foo.bar.

No, Source is Source (remote). 

You have to set:
 "IPCop_External_Destination":<Port> to "Internal_Destination":<port> 

Packets are coming from <Remote>:<Random port> --->
"IPCop_External_Destination":<Port>  --->  "Internal_Destination":<port> 

"Source Port" in IPCop Firewall ui is the source (remote) port. As this is port
is random your rules do not match.


best regards

Achim

------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk