Nocat gateway + IPFW2 is not work?
amon <[email protected]>
| Newsgroups | gmane.network.nocat |
|---|---|
| Message-ID | <[email protected]> |
Thanks to Scott E. Campbell and Jacob S. Barrett.
The default ipfw in FreeBSD4.8realese is ipfw1 not ipfw2.
I re-make install ipfw2 and kernel,then the nocat gateway is active.
But i still can't get the captive web page of my nocat auth server.
My physical structure:
Internet
|
|
|fxp0, 220.228.XX.48
____|_____
|gateway |
|________|
|bge0, 220.228.XX.181
|
|
| ____
___|__| |
| |AP| ))))))))))))
| |__| wlan0, 220.228.XX.182
| ______ __|____
|___________| | | |
eth0, |PC 1| | PC2 |
220.228.XX.183 |____| |_____|
three sub net:
220.228.XX.0/25
220.228.XX.128/26
220.228.XX.192/26
Because i want to use nocat gateway as bridge,
i add three lines to bin/initialize.fw
sysctl net.link.ether.bridge_ipfw=1
sysctl net.link.ether.bridge=1
sysctl net.link.ether.bridge_cfg=fxp0,bge0
Then runs nocat gateway.
But PC1,PC2 can browse Internet directly by
"allow log ip from any to any layer2".
So i delete this rule "allow log ip from any to any layer2",
and PC1,PC2 can't browse anywhere.
In this state, fwd rule is working,
All pocket from 220.228.XX.XXX to any,80 will forward 220.228.XX.181,5280.
But in next step, the orignal pocket(from 220.228.XX.XX to any,80) is
Deny by "02000 deny log ip from any to any".
Is gateway daemon working?
It's jod(motify header of pocket) seems not work well.
thanks for any suggestion.
amonrose
Below is my nocat.conf, firewall rules and pocket log of my bridge.
===========
nocat.conf:
Verbosity 10
GatewayName the Xeon Network
GatewayMode Passive
GatewayLog /usr/local/gw/Xeongateway.log
LoginTimeout 600
HomePage http://www.XXXX.net/
TrustedGroups Any
AuthServiceAddr wlan.XXXX.net
AuthServiceURL https://$AuthServiceAddr/
LogoutURL https://$AuthServiceAddr/logout.html
ExternalDevice fxp0
InternalDevice bge0
LocalNetwork 220.228.XX.128/26
DNSAddr 168.95.XX.1
ExcludePorts 25
ResetCmd initialize.fw
PermitCmd access.fw permit $MAC $IP $Class
DenyCmd access.fw deny $MAC $IP $Class
StatsCmd stats.fw $MAC $IP
GatewayPort 5280
GatewayAddr 220.228.XX.181
AccountingMethod None
==1111/13:28/Thu[root@gw] bin/gateway
[2004-11-11 12:09:23] Resetting firewall.
net.inet.ip.forwarding: 1 -> 1
net.link.ether.ipfw: 1 -> 1
net.link.ether.bridge_ipfw: 1 -> 1
net.link.ether.bridge: 1 -> 1
net.link.ether.bridge_cfg: fxp0,bge0 -> fxp0,bge0
01100 allow log ip from any to any via fxp0
01200 allow log ip from any to any via lo0
01300 allow log tcp from any to any dst-port 5280 in via bge0
01400 allow log tcp from any to any dst-port 5280 out via bge0
01500 allow log tcp from any to any dst-port 22 in via bge0
01600 allow log tcp from any to any dst-port 22 out via bge0
01700 allow log udp from any to 168.95.XX.1 dst-port 53 in via bge0
keep-state
01800 allow log tcp from any to 220.228.XX.46 dst-port 80,443 in via bge0
01900 fwd 220.228.XX.181,5280 log tcp from any to any dst-port 80,443 in
via bge0
02000 deny log ip from any to any
60000 queue 1 ip from any to any in
60000 queue 2 ip from any to any out
60010 skipto 61000 ip from any to any
60100 queue 3 ip from any to any in
60100 queue 4 ip from any to any out
60110 skipto 61000 ip from any to any
[2004-11-11 12:09:23] Binding listener socket to 220.228.XX.181
==1111/13:28/Thu[root@gw] tail -f /var/log/security
13:30:49 XXX /kernel: ipfw: 1700 Accept UDP 220.228.XX.182:1039
168.95.XX.1:53 in via bge0
13:30:49 XXX /kernel: ipfw: 1100 Accept UDP 168.95.XX.1:53
220.228.XX.182:1039 in via fxp0
13:30:49 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1453 66.94.230.47:80 in via bge0
13:30:49 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1453
66.94.230.47:80 in via bge0
13:30:52 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1453 66.94.230.47:80 in via bge0
13:30:52 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1453
66.94.230.47:80 in via bge0
13:30:53 XXX /kernel: ipfw: 1700 Accept UDP 220.228.XX.182:1039
168.95.XX.1:53 in via bge0
13:30:53 XXX /kernel: ipfw: 1100 Accept UDP 168.95.XX.1:53
220.228.XX.182:1039 in via fxp0
13:30:53 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1454 207.46.104.20:80 in via bge0
13:30:53 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1454
207.46.104.20:80 in via bge0
13:30:56 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1454 207.46.104.20:80 in via bge0
13:30:56 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1454
207.46.104.20:80 in via bge0
13:30:58 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1453 66.94.230.47:80 in via bge0
13:30:58 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1453
66.94.230.47:80 in via bge0
13:30:58 XXX /kernel: ipfw: 1700 Accept UDP 220.228.XX.182:1039
168.95.XX.1:53 in via bge0
13:30:58 XXX /kernel: ipfw: 1100 Accept UDP 168.95.XX.1:53
220.228.XX.182:1039 in via fxp0
13:31:03 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1456 207.46.104.20:80 in via bge0
13:31:03 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1456
207.46.104.20:80 in via bge0
13:31:05 XXX /kernel: ipfw: 2000 Deny UDP 192.168.199.126:68
255.255.255.255:67 in via bge0
13:31:05 XXX /kernel: ipfw: 2000 Deny UDP 192.168.199.126:68
255.255.255.255:67 in via bge0
13:31:06 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1456 207.46.104.20:80 in via bge0
13:31:06 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1456
207.46.104.20:80 in via bge0
13:31:10 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1457 66.94.230.50:80 in via bge0
13:31:10 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1457
66.94.230.50:80 in via bge0
13:31:13 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1457 66.94.230.50:80 in via bge0
13:31:13 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1457
66.94.230.50:80 in via bge0
13:31:19 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1457 66.94.230.50:80 in via bge0
13:31:19 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1457
66.94.230.50:80 in via bge0