Re: [Security Firewall] Problem with port forwarding

"ibon M. B." <[email protected]>
Newsgroups gmane.linux.mandrake.security.firewall
Message-ID <[email protected]>
this the log of \var\log\syslog when i tiry to connect from an external 
machine:
Jun 14 20:43:37 localhost kernel: Shorewall:lan2all:DROP:IN=eth1 OUT=eth0 
SRC=192.168.1.100 DST=192.168.0.202 LEN=76 TOS=0x00 PREC=0x00 TTL=127 
ID=8840 PROTO=UDP SPT=123 DPT=123 LEN=56
Jun 14 20:43:53 localhost kernel: Shorewall:lan2all:DROP:IN=eth1 OUT=eth0 
SRC=192.168.1.100 DST=192.168.0.202 LEN=76 TOS=0x00 PREC=0x00 TTL=127 
ID=8841 PROTO=UDP SPT=123 DPT=123 LEN=56
Jun 14 20:44:00 localhost CROND[22558]: (root) CMD (   
/usr/share/msec/promisc_check.sh)
Jun 14 20:44:09 localhost kernel: Shorewall:lan2all:DROP:IN=eth1 OUT=eth0 
SRC=192.168.1.100 DST=192.168.0.202 LEN=76 TOS=0x00 PREC=0x00 TTL=127 
ID=8842 PROTO=UDP SPT=123 DPT=123 LEN=56
Jun 14 20:44:25 localhost kernel: Shorewall:lan2all:DROP:IN=eth1 OUT=eth0 
SRC=192.168.1.100 DST=192.168.0.202 LEN=76 TOS=0x00 PREC=0x00 TTL=127 
ID=8843 PROTO=UDP SPT=123 DPT=123 LEN=56

why is mnf blocking access on port 123?? better...why the ftp conecction is 
establishing on port 123?...if i´m not misunderstanding the logs
>From: Neill Mitchell <[email protected]>
>Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
>To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
>Subject: Re: [Security Firewall] Problem with port forwarding
>Date: Tue, 14 Jun 2005 13:18:49 +0000
>
>One thing to try to eliminate certain things. Have you tried to connect to 
>the
>ftp machine from an external machine? I assume you have the NAT all
>configured correctly for this machine (i.e. you are not trying to access it
>externally via its internal address)?
>
>Cheers
>On Tuesday 14 Jun 2005 10:06, ibon M. B. wrote:
> > Thanks for your help
> > I have created a custom rule to forward the ftp traffic to a computer in 
>my
> > lan, but port forwarding doesn´t seem to work.
> > Custom Rule:
> > Result --DNAT
> > Predefined Services--FTP
> > Protocol--FTP
> > Client:WAN
> > Server:LAN 192.168.1.100
> > Forwarding Address:all
> >
> > i can connect the ftp server inside the lan, but not outside.
> > any ideas?
> >
> >
> >
> >
> >
> > _____________________________________________________________________
> > This message has been checked for all known viruses by Minuco delivered
> > through the MessageLabs Virus Scanning Service. For further infomation
> > visit http://www.minuco.com or alternatively mail [email protected]
>
>--
>Best regards
>Neill Mitchell
>
>Minuco Vigilize
>31 Museum Street, London, WC1A 1LG
>
>T: +44 (0)20 7692 2649
>F: +44 (0)20 7436 9955
>
>http://www.minuco.com <http://www.minuco.com/>
>
>You have received this e-mail from Minuco. It is intended to be read by
>the addressee because it could contain confidential and privileged
>information (including any attachments). If you are not the person or
>organisation this e-mail was intended for please return it to the sender
>and delete it from your computer(s). You must not copy, distribute,
>disclose, or disseminate the contents of this e-mail or its attachments
>to any third party unless authorised by Minuco.
>
>It is the responsibility of the recipient to ensure that the forwarding,
>opening or use of the e-mail (and any attachments) will not adversely
>affect their systems or data. Please carry out appropriate virus checks.
>
>All rights reserved. The intellectual property in this e-mail and any
>attachments are vested solely in Minuco.
>
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.