Re: is nocat working properly?
"Todd A. May" <[email protected]>
| Newsgroups | gmane.network.nocat |
|---|---|
| Message-ID | <010201c4a2b1$25d4a320$1b01a8c0@foo> |
All, I have a NTP server running on our nocat auth/gw server and it's sync'd and operating fine. I attempted to redirect all NTP traffic from the wireless side to the eth1 (wireless address) in an attempt to spoof any attempts the AP's had on communicating with external time sources. Although the packets were redirected to the ETH1's address and a response was made... The wrt54g w/ sveasoft keep indicating they can't update their time. I got fed up with the local attempt and tried opening up nocat similar to how it allows certain web addresses to be accessed (this part works on ours). here is a snippet of the end of my initialize.fw ### Newest NTP attempts $nat -s 192.169.2.0 -p udp --dport 123 -j MASQUERADE $redirect -s 192.169.2.0 -p udp --dport 123 -j RETURN $fwd -s 192.169.2.0 -p udp --dport 123 -j ACCEPT $fwd -d 192.169.2.0 -p udp --sport 123 -j ACCEPT Here is a snippet from iptables: ACCEPT udp -- 192.169.2.0 anywhere udp dpt:ntp ACCEPT udp -- anywhere 192.169.2.0 udp spt:ntp So... Why doesn't this work? Any thoughts? --Todd ----- Original Message ----- From: "chris neitzert" <[email protected]> To: "David Bowman" <[email protected]> Cc: <[email protected]> Sent: Friday, September 24, 2004 12:31 PM Subject: Re: [NoCat] is nocat working properly? > David > > I'm not sure how this works in nocat with the two separate layers of > users, in my configuration you are granted full user access, or you are > not and therefore only allowed to access my websites. > > However in iptables I would probably approach it to write and specific > rules to your initialize.fw script for the specific access class that > specifically say 80/443 are permitted and everything else is dropped. > > something like: > > $ports - p tcp -i $iface --dport 80 -m mark --mark 3 -j ACCEPT > $ports - p tcp -i $iface --dport 443 -m mark --mark 3 -j ACCEPT > > (I'm not exactly sure if 3 is co-op or public class - might wanna check > that) > > > However, I too am not exceedingly familiar with IPtables, I just have a > basic knowledge of it and I have found this, albeit old, tutorial pretty > helpful: http://iptables-tutorial.frozentux.net/iptables-tutorial.html > > best > > chris > > > David Bowman wrote: > > > Thanks Chris! > > > > My GatewayMode is Passive > > > > I am using the default login page. (with the "skip" button) > > > > I can also login at that point with a user account, and have full access on all ports. > > > > Is this the default behavior of nocat or is my setup not running right: > > "skip" users have only access to the domain of their homepage. > > "logged in" users have full access. > > > > I would like to limit access for logged in users (co-op class correct?) to just > > ports 80, 443. I would then disallow skipping. (Just my preference for experimentation) > > > > I found that if I changed initialize.fw to attempt to limit access for > > "logged in users" (class 2 users) I ended up making it behave like a > > "skipped" user (class 3 user) I could only hit my homepage. > > > > I have IncludePorts = 80 443 > > > > If I change the initialize.fw script like the following: > > #Enable all ports in IncludePorts > > for iface in $IncludePorts; do > > $ports - p tcp -i $iface --dport $port -m mark --mark 3 -j ACCEPT > > $ports - p udp -i $iface --dport $port -m mark --mark 3 -j ACCEPT > > $ports - p tcp -i $iface --dport $port -m mark --mark 2 -j ACCEPT > > $ports - p udp -i $iface --dport $port -m mark --mark 2 -j ACCEPT > > (added last two lines for class 2) > > > > farther below...in initialize.fw: > > > > # ...and disable access to the rest. > > $ports - p tcp -i $iface --dport $port -m mark --mark 3 -j DROP > > $ports - p udp -i $iface --dport $port -m mark --mark 3 -j DROP > > $ports - p tcp -i $iface --dport $port -m mark --mark 2 -j DROP > > $ports - p udp -i $iface --dport $port -m mark --mark 2 -j DROP > > (added last two lines for class 2) > > > > Then I restart the gateway, and I login with a username and password, > > I end up with the same access level as a "skipped" user. > > (I can only browse my homepage) > > > > This access level is 3 correct? (public class) > > > > What I don't understand is where the rules are being created to limit my access > > to just my homepage. (the first page I hit) > > > > I'm new to tweaking firewall rules in linux. The way I'm reading the statements > > in initialize.fw it seems that I should be able to browse ANY website on ports 80 and 443 > > > > My goal is to be able to allow logged in users (co-op) to be able to browse webpages only. > > > > I must be missing something. Thanks for any help. > > David > > > > chris neitzert <[email protected]> wrote: > > David > > that depends, how is your NoCat configured (see nocat.conf) > > # GatewayMode -- Determines the mode of operation of the gateway. Possible > > # values are: > > # > > # Captive - Allow authentication against an auth service. LEGACY. > > # Passive - Like Captive, but YOU MUST USE THIS if your gateway > > # is behind a NAT. Will work anyway if not. *RECOMMENDED*. > > # Open - Simply require a user to view a splash page and accept > > # a use agreement. > > and if you are using login or login_no_skip > > What i've done on my portal is to remove the skip button from the forms > > on all of login pages and symbolicaly link everything to the > > login_no_skip page. > > chris > > > > David Bowman wrote: > > > >>I have nocat .82 gateway and auth on same machine (running fc2) Just experimenting with nocat. > >> > >>When I click on "skip" at the login page, I get redirected to my homepage (www.google.com set in browser). But at that point I can only browse pages on that domain. (www.google.com) > >> > >>Does anyone know if this is the default behavior of the nocat system with .82??? > >> > >>Or should I be able to browse any website (after clicking "skip") on ports 80 and 443??? > >> > >>Just a confirmation would be much appreciated so I can do further work with nocat. > >>Thanks. > >> > >> > >> > >>__________________________________________________ > >>Do You Yahoo!? > >>Tired of spam? Yahoo! Mail has the best spam protection around > >>http://mail.yahoo.com > >> > >> > >>------------------------------------------------------------------------ > >> > >>_______________________________________________ > >>NoCat mailing list > >>[email protected] > >>http://lists.nocat.net/mailman/listinfo/nocat > > > > > > > > > > --------------------------------- > > Do you Yahoo!? > > vote.yahoo.com - Register online to vote today! > _______________________________________________ > NoCat mailing list > [email protected] > http://lists.nocat.net/mailman/listinfo/nocat >