RE: [Security Firewall] Re: port forwarding
"Ibon Merino" <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.firewall |
|---|---|
| Message-ID | <[email protected]> |
THANKS...that was the problem, the router redirected the traffic to the internal MNF IP address. Thanks for your time -----Mensaje original----- De: security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected] [mailto:security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]] En nombre de florin Enviado el: jueves, 16 de junio de 2005 9:34 Para: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] Asunto: [Security Firewall] Re: port forwarding the router has to redirect the ftp traffic to the external MNF IP address, not to your ftp server directly. On 6/15/05, ibon M. B. <[email protected]> wrote: > thanks for your help and I apologize because of my english > I have created a custom rule to forward the ftp traffic to a computer in my > lan, but port forwarding doesn´t seem to work. The FTP server is up and > runnig (I can access it inside my lan), but I can not access it outside, > even var/log/syslog does not show any attempt of coneection. > > the router (192.168.10.1) redirects all traffic in ports 20/21 to the > internal ip of then ftp server(192.168.1.101) (I ve tried also redirecting > to the firewall (192.168.10.254/192.168.1.254) > > I have read all the messages on the mailing list and I have tried every > possible (I think) configuration in the rules and every possible solution in > the lists, but nothing seems to work > have you ideas of what am I doing wrong? > > thanks again > > > > # > #--------------------------------------------------------- > # DO NOT MODIFY THIS FILE! It is updated automatically > # by the naat/backend. Modify the template file instead > # in /usr/share/naat/templates/etc/shorewall > #--------------------------------------------------------- > # > # Copyright (C) 2002 Mandrakesoft > # Author Florin Grad > # > #--------------------------------------------------------- > # Shorewall /etc/shorewall/interfaces > > > #zone interface broadcast options > wan eth0 detect > lan eth1 detect > #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE > > > # > #--------------------------------------------------------- > # DO NOT MODIFY THIS FILE! It is updated automatically > # by the naat/backend. Modify the template file instead > # in /usr/share/naat/templates/etc/shorewall > #--------------------------------------------------------- > # > # Copyright (C) 2002 Mandrakesoft > # Author Florin Grad > # > #--------------------------------------------------------- > # Shorewall /etc/shorewall/policy > > > #client server policy log_level > lan all DROP info > dmz all DROP info > fw all DROP info > wan all DROP info > all all DROP info > #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE > > > # > #--------------------------------------------------------- > # DO NOT MODIFY THIS FILE! It is updated automatically > # by the naat/backend. Modify the template file instead > # in /usr/share/naat/templates/etc/shorewall > #--------------------------------------------------------- > # > # Copyright (C) 2002 Mandrakesoft > # Author Florin Grad > # > #--------------------------------------------------------- > # Shorewall /etc/shorewall/zones > > > #zone display comments > lan LAN local_area_network > dmz DMZ demilitarized_zone > wan NET internet > #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE > > > # > #--------------------------------------------------------- > # DO NOT MODIFY THIS FILE! It is updated automatically > # by the naat/backend. Modify the template file instead > # in /usr/share/naat/templates/etc/shorewall > #--------------------------------------------------------- > # > # Copyright (C) 2002 Mandrakesoft > # Author Florin Grad > # > #--------------------------------------------------------- > # Shorewall /etc/shorewall/rules > > > #result client server proto port client_port address > ACCEPT fw wan tcp 53 - > ACCEPT fw wan udp 53 - > ACCEPT lan wan udp 53 - > ACCEPT lan fw tcp 22 - > ACCEPT lan fw tcp 8443 - > ACCEPT fw lan icmp 8 - > ACCEPT:info lan fw icmp 8 - > ACCEPT lan wan tcp pop3 - > ACCEPT lan wan tcp smtp - > ACCEPT:info lan wan tcp http - > ACCEPT lan wan tcp https - > ACCEPT lan wan tcp ssh - > ACCEPT lan wan tcp nntp - > ACCEPT fw wan udp ntp - > ACCEPT lan wan tcp imap - > ACCEPT lan fw udp 53 - > ACCEPT lan fw tcp 139 - > ACCEPT fw lan tcp 139 - > ACCEPT lan wan icmp echo-request - > ACCEPT lan fw::3328 tcp www - all > ACCEPT fw wan tcp www - > ACCEPT lan:192.168.1.42 wan tcp telnet - > ACCEPT lan wan tcp 1723 - > ACCEPT lan wan gre - - > ACCEPT wan fw tcp ftp - > ACCEPT wan fw tcp ftp-data - > DNAT wan lan:192.168.1.101 tcp ftp - 213.98.153.32 > DNAT wan lan:192.168.1.101 tcp ftp-data - all > ACCEPT wan lan:192.168.1.101 tcp ftp - all > DNAT wan lan:192.168.1.101 tcp 5900 - all > #LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE > > > -- Florin
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________