[Security Firewall] Re: port forwarding

florin <[email protected]>
Newsgroups gmane.linux.mandrake.security.firewall
Message-ID <[email protected]>
the router has to redirect the ftp traffic to the external MNF IP
address, not to your ftp server directly.

On 6/15/05, ibon M. B. <[email protected]> wrote:
> thanks for your help and I apologize because of my english
> I have created a custom rule to forward the ftp traffic to a computer in my
> lan, but port forwarding doesn´t seem to work. The FTP server is up and
> runnig (I can access it inside my lan), but I can not access it outside,
> even var/log/syslog does not show any attempt of coneection.
> 
> the router (192.168.10.1) redirects all traffic in ports 20/21 to the
> internal ip of then ftp server(192.168.1.101) (I ve tried also redirecting
> to the firewall (192.168.10.254/192.168.1.254)
> 
> I have read all the messages on the mailing list and I have tried every
> possible (I think) configuration in the rules and every possible solution in
> the lists, but nothing seems to work…
> have you ideas of what am I doing wrong?
> 
> thanks again
> 
> 
> 
> #
> #---------------------------------------------------------
> # DO NOT MODIFY THIS FILE! It is updated automatically
> # by the naat/backend. Modify the template file instead
> # in /usr/share/naat/templates/etc/shorewall
> #---------------------------------------------------------
> #
> # Copyright (C) 2002 Mandrakesoft
> # Author Florin Grad
> #
> #---------------------------------------------------------
> # Shorewall /etc/shorewall/interfaces
> 
> 
> #zone   interface       broadcast       options
> wan     eth0    detect
> lan     eth1    detect
> #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE
> 
> 
> #
> #---------------------------------------------------------
> # DO NOT MODIFY THIS FILE! It is updated automatically
> # by the naat/backend. Modify the template file instead
> # in /usr/share/naat/templates/etc/shorewall
> #---------------------------------------------------------
> #
> # Copyright (C) 2002 Mandrakesoft
> # Author Florin Grad
> #
> #---------------------------------------------------------
> # Shorewall /etc/shorewall/policy
> 
> 
> #client server  policy  log_level
> lan     all     DROP    info
> dmz     all     DROP    info
> fw      all     DROP    info
> wan     all     DROP    info
> all     all     DROP    info
> #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE
> 
> 
> #
> #---------------------------------------------------------
> # DO NOT MODIFY THIS FILE! It is updated automatically
> # by the naat/backend. Modify the template file instead
> # in /usr/share/naat/templates/etc/shorewall
> #---------------------------------------------------------
> #
> # Copyright (C) 2002 Mandrakesoft
> # Author Florin Grad
> #
> #---------------------------------------------------------
> # Shorewall /etc/shorewall/zones
> 
> 
> #zone   display comments
> lan     LAN     local_area_network
> dmz     DMZ     demilitarized_zone
> wan     NET     internet
> #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE
> 
> 
> #
> #---------------------------------------------------------
> # DO NOT MODIFY THIS FILE! It is updated automatically
> # by the naat/backend. Modify the template file instead
> # in /usr/share/naat/templates/etc/shorewall
> #---------------------------------------------------------
> #
> # Copyright (C) 2002 Mandrakesoft
> # Author Florin Grad
> #
> #---------------------------------------------------------
> # Shorewall /etc/shorewall/rules
> 
> 
> #result client  server  proto   port    client_port     address
> ACCEPT  fw      wan     tcp     53      -
> ACCEPT  fw      wan     udp     53      -
> ACCEPT  lan     wan     udp     53      -
> ACCEPT  lan     fw      tcp     22      -
> ACCEPT  lan     fw      tcp     8443    -
> ACCEPT  fw      lan     icmp    8       -
> ACCEPT:info     lan     fw      icmp    8       -
> ACCEPT  lan     wan     tcp     pop3    -
> ACCEPT  lan     wan     tcp     smtp    -
> ACCEPT:info     lan     wan     tcp     http    -
> ACCEPT  lan     wan     tcp     https   -
> ACCEPT  lan     wan     tcp     ssh     -
> ACCEPT  lan     wan     tcp     nntp    -
> ACCEPT  fw      wan     udp     ntp     -
> ACCEPT  lan     wan     tcp     imap    -
> ACCEPT  lan     fw      udp     53      -
> ACCEPT  lan     fw      tcp     139     -
> ACCEPT  fw      lan     tcp     139     -
> ACCEPT  lan     wan     icmp    echo-request    -
> ACCEPT  lan     fw::3328        tcp     www     -       all
> ACCEPT  fw      wan     tcp     www     -
> ACCEPT  lan:192.168.1.42        wan     tcp     telnet  -
> ACCEPT  lan     wan     tcp     1723    -
> ACCEPT  lan     wan     gre     -       -
> ACCEPT  wan     fw      tcp     ftp     -
> ACCEPT  wan     fw      tcp     ftp-data        -
> DNAT    wan     lan:192.168.1.101       tcp     ftp     -       213.98.153.32
> DNAT    wan     lan:192.168.1.101       tcp     ftp-data        -       all
> ACCEPT  wan     lan:192.168.1.101       tcp     ftp     -       all
> DNAT    wan     lan:192.168.1.101       tcp     5900    -       all
> #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE
> 
> 
> 


-- 
Florin
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.