Next-in-Thread Next Message Previous Message Next Thread

Question: Packets droped in between NAT and ipchains under 2.1.125

Forum: Linux IP NAT Forum
Keywords: localhost
Date: Tue, 16 Feb 1999 21:39:22 GMT
From: Me <anik@ifdo.pugmarks.com>

I'v been trying to set up a NAT server and have been running into a big problem: packets seem to drop in between IP NAT and ipchains. ie with all packets being loged both at all points posible, I get the 2 NAT messages, then nothing, when you should get the input fire wall rule.
my setup is as folows:
    net A:---------:A nat B:-----------:routerB:---:compB
2.2.2.0/24 2.2.3.2/32 3.2.2.2/32 3.2.2.1/32 3.2.3.2/32
net A wants to comunicate to compB using address natA as destination. NetB doesn't like packets that have addresses of Abut perfectly likes that of netC (3.2.4.0/24), so here's where nat comes in.
RouterB knows that packets of dest netC have a gatway of natB.
So everything goes to compB fine, just while coming back, at nat B packets enter nat B get changed to a source of nat A and droped befor or by the firewalling code.
In the routeing code (route.c) it is said that all packets having a local source address should be droped and I think that's where the problem is coming from.
I have little knoledge of c so I don't know what to change.
the -b flag doesn't seem to work (only the direction inicated gets translated), nyther does the using a -O for some reason (it seems to only get hooked for packets that originate from the computer ie. not the forwarded ones). I'v tried using autofw but it doesn't seem to recognize it's own packets.
Any sugestions?
Nota: all ip's are fictif
my commands are:
ipnatadm -F
ipnatadm -I -i -S 3.2.3.2/32 -D 3.2.4.0/24 -N 2.2.2.0/24 -M 2.2.3.2/32 -v -P tcp
ipnatadm -I -i -S 2.2.2.0/24 -D 2.2.3.2/32 -M 3.2.4.0/24 -N 3.2.3.2/32 -v -P tcp
Me

Next-in-Thread Next Message Previous Message Next Thread

Messages Inline: 1 All Outline: 1 2 3

1. More: Verry dirty fix... by Me, 2/17/99

to: "Packets droped in between NAT and ipchains under 2.1.125"

Subscribe Membership Move/Remove Admin Mode Help for HyperNews 1.9.5