Nocat gateway + IPFW2 is not work?

amon <[email protected]>
Newsgroups gmane.network.nocat
Message-ID <[email protected]>
Thanks to Scott E. Campbell and Jacob S. Barrett.

The default ipfw in FreeBSD4.8realese is ipfw1 not ipfw2.
I re-make install ipfw2 and kernel,then the nocat gateway is active.
But i still can't get the captive web page of my nocat auth server.

My physical structure:

    Internet
           |
           |
           |fxp0, 220.228.XX.48
       ____|_____
       |gateway |
       |________|
           |bge0, 220.228.XX.181
           |
           |
           |  ____
        ___|__|  |
        |     |AP|  ))))))))))))
        |     |__|         wlan0, 220.228.XX.182
        |           ______       __|____
        |___________|    |       |     |
    eth0,           |PC 1|       | PC2 |
    220.228.XX.183  |____|       |_____|

    three sub net:
        220.228.XX.0/25
        220.228.XX.128/26
        220.228.XX.192/26


Because i want to use nocat gateway as bridge,
i add three lines to bin/initialize.fw
   sysctl net.link.ether.bridge_ipfw=1
   sysctl net.link.ether.bridge=1
   sysctl net.link.ether.bridge_cfg=fxp0,bge0
Then runs nocat gateway.
But PC1,PC2 can browse Internet directly by
"allow log ip from any to any layer2".
So i delete this rule "allow log ip from any to any layer2",
and PC1,PC2 can't browse anywhere.

In this state, fwd rule is working,
All pocket from 220.228.XX.XXX to any,80 will forward 220.228.XX.181,5280.
But in next step, the orignal pocket(from 220.228.XX.XX to any,80) is
Deny by "02000 deny log ip from any to any".
Is gateway daemon working?
It's jod(motify header of pocket) seems not work well.

thanks for any suggestion.
amonrose

Below is my nocat.conf, firewall rules and pocket log of my bridge.
===========
nocat.conf:

Verbosity           10
GatewayName         the Xeon Network
GatewayMode         Passive
GatewayLog          /usr/local/gw/Xeongateway.log
LoginTimeout        600
HomePage            http://www.XXXX.net/
TrustedGroups       Any
AuthServiceAddr     wlan.XXXX.net
AuthServiceURL      https://$AuthServiceAddr/
LogoutURL           https://$AuthServiceAddr/logout.html
ExternalDevice      fxp0
InternalDevice      bge0
LocalNetwork        220.228.XX.128/26
DNSAddr             168.95.XX.1
ExcludePorts        25
ResetCmd            initialize.fw
PermitCmd           access.fw permit $MAC $IP $Class
DenyCmd             access.fw deny $MAC $IP $Class
StatsCmd            stats.fw $MAC $IP
GatewayPort         5280
GatewayAddr         220.228.XX.181
AccountingMethod    None

==1111/13:28/Thu[root@gw] bin/gateway

[2004-11-11 12:09:23] Resetting firewall.
net.inet.ip.forwarding: 1 -> 1
net.link.ether.ipfw: 1 -> 1
net.link.ether.bridge_ipfw: 1 -> 1
net.link.ether.bridge: 1 -> 1
net.link.ether.bridge_cfg: fxp0,bge0 -> fxp0,bge0
01100 allow log ip from any to any via fxp0
01200 allow log ip from any to any via lo0
01300 allow log tcp from any to any dst-port 5280 in via bge0
01400 allow log tcp from any to any dst-port 5280 out via bge0
01500 allow log tcp from any to any dst-port 22 in via bge0
01600 allow log tcp from any to any dst-port 22 out via bge0
01700 allow log udp from any to 168.95.XX.1 dst-port 53 in via bge0
keep-state
01800 allow log tcp from any to 220.228.XX.46 dst-port 80,443 in via bge0
01900 fwd 220.228.XX.181,5280 log tcp from any to any dst-port 80,443 in
via bge0
02000 deny log ip from any to any
60000 queue 1 ip from any to any in
60000 queue 2 ip from any to any out
60010 skipto 61000 ip from any to any
60100 queue 3 ip from any to any in
60100 queue 4 ip from any to any out
60110 skipto 61000 ip from any to any
[2004-11-11 12:09:23] Binding listener socket to  220.228.XX.181

==1111/13:28/Thu[root@gw] tail -f /var/log/security

13:30:49 XXX /kernel: ipfw: 1700 Accept UDP 220.228.XX.182:1039
168.95.XX.1:53 in via bge0
13:30:49 XXX /kernel: ipfw: 1100 Accept UDP 168.95.XX.1:53
220.228.XX.182:1039 in via fxp0
13:30:49 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1453 66.94.230.47:80 in via bge0
13:30:49 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1453
66.94.230.47:80 in via bge0
13:30:52 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1453 66.94.230.47:80 in via bge0
13:30:52 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1453
66.94.230.47:80 in via bge0
13:30:53 XXX /kernel: ipfw: 1700 Accept UDP 220.228.XX.182:1039
168.95.XX.1:53 in via bge0
13:30:53 XXX /kernel: ipfw: 1100 Accept UDP 168.95.XX.1:53
220.228.XX.182:1039 in via fxp0
13:30:53 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1454 207.46.104.20:80 in via bge0
13:30:53 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1454
207.46.104.20:80 in via bge0
13:30:56 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1454 207.46.104.20:80 in via bge0
13:30:56 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1454
207.46.104.20:80 in via bge0
13:30:58 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1453 66.94.230.47:80 in via bge0
13:30:58 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1453
66.94.230.47:80 in via bge0
13:30:58 XXX /kernel: ipfw: 1700 Accept UDP 220.228.XX.182:1039
168.95.XX.1:53 in via bge0
13:30:58 XXX /kernel: ipfw: 1100 Accept UDP 168.95.XX.1:53
220.228.XX.182:1039 in via fxp0
13:31:03 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1456 207.46.104.20:80 in via bge0
13:31:03 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1456
207.46.104.20:80 in via bge0
13:31:05 XXX /kernel: ipfw: 2000 Deny UDP 192.168.199.126:68
255.255.255.255:67 in via bge0
13:31:05 XXX /kernel: ipfw: 2000 Deny UDP 192.168.199.126:68
255.255.255.255:67 in via bge0
13:31:06 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1456 207.46.104.20:80 in via bge0
13:31:06 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1456
207.46.104.20:80 in via bge0
13:31:10 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1457 66.94.230.50:80 in via bge0
13:31:10 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1457
66.94.230.50:80 in via bge0
13:31:13 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1457 66.94.230.50:80 in via bge0
13:31:13 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1457
66.94.230.50:80 in via bge0
13:31:19 XXX /kernel: ipfw: 1900 Forward to 220.228.XX.181:5280 TCP
220.228.XX.182:1457 66.94.230.50:80 in via bge0
13:31:19 XXX /kernel: ipfw: 2000 Deny TCP 220.228.XX.182:1457
66.94.230.50:80 in via bge0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.