Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-13-2004, 02:19 PM
Junior Member
 
Join Date: Sep 2003
Posts: 15
Default Problems with network configuration

I have a class C public network. I've split the class C into 3 parts and defined them on interfaces 0-2. Now I want to use the 192.168-class C on my interface 3. I defined eth3 as 192.168.1.1 and activated masquerading on this port. Now I can reach all systems in my class C from the internal network but not in the internet. Can someone give me a hand please ?
Reply With Quote
  #2 (permalink)  
Old 01-13-2004, 02:22 PM
Junior Member
 
Join Date: Sep 2003
Posts: 15
Default Re: Problems with network configuration

My 3 parts are on 1-3 of course and 0 is my way into the internet. 4 is supposed to be internal with enabled masquerading.
Reply With Quote
  #3 (permalink)  
Old 01-13-2004, 03:11 PM
Wizard
 
Join Date: Jul 2003
Location: U.S.
Posts: 1,265
Default Re: Problems with network configuration

Openers:
<ul type="square">[*]gateway to Internet set on Internet interface?[*]what does a traceroute out say?[/list]
Reply With Quote
  #4 (permalink)  
Old 01-13-2004, 04:08 PM
AJo AJo is offline
Senior Member
 
Join Date: Mar 2002
Location: sweden
Posts: 140
Default Re: Problems with network configuration

myself:
[ QUOTE ]
I have a class C public network. I've split the class C into 3 parts and defined them on interfaces 0-2

[/ QUOTE ]
3 parts?
/25 = 2 subnets
/26 = 4 subnets
/27 = 8 subnets

Dont quite follow what you mean and what you are trying to accomplish. Are you trying to split the public /24 net into subnets to use behind the ASL box?
Reply With Quote
  #5 (permalink)  
Old 01-14-2004, 08:09 AM
Junior Member
 
Join Date: Sep 2003
Posts: 15
Default Re: Problems with network configuration

[ QUOTE ]
Openers:
<ul type="square">[*]gateway to Internet set on Internet interface?[*]what does a traceroute out say?[/list]

[/ QUOTE ]

Gateway is set, I can reach the internet from the public available IP's without any problems. Traceroute ends at 192.168.1.1 (eth4 of ASL).

I read somewhere in the forum that there are some problems with the masquerading feature of the ASL Kernel. Can someone verify this?
Reply With Quote
  #6 (permalink)  
Old 01-14-2004, 08:12 AM
Junior Member
 
Join Date: Sep 2003
Posts: 15
Default Re: Problems with network configuration

[ QUOTE ]

Dont quite follow what you mean and what you are trying to accomplish. Are you trying to split the public /24 net into subnets to use behind the ASL box?

[/ QUOTE ]

I did split the /24 into one /25 (eth1) and two /26 (eth2 and 3). This is working without any problems. I want to add a private network on eth4 but this does not work.
Reply With Quote
  #7 (permalink)  
Old 01-14-2004, 10:19 PM
Wizard
 
Join Date: Jul 2003
Location: U.S.
Posts: 1,265
Default Re: Problems with network configuration

This is still sketchy for me; can you just enumerate the network numbers and masks on your interfaces, and your packetfilter and masquerading rules? Conceal any 'real' IP addresses...








Reply With Quote
  #8 (permalink)  
Old 01-15-2004, 08:21 AM
Junior Member
 
Join Date: Sep 2003
Posts: 15
Default Re: Problems with network configuration

Ok, I'll try. Let's say my public IP range is 100.0.0.0/24 and my gateway is 99.0.0.1, then I have the following settings:

eth0: 99.0.0.2/29 with gateway 99.0.0.1
eth1: 100.0.0.1/26
eth2: 100.0.0.65/26
eth3: 100.0.0.129/25
eth4: 192.168.1.1/24 (called "private")

I have defined the rule <font color="blue">private_network -> Any -> Any -> Allow </font>
And NAT rule <font color="blue"> Masquerading / private_network / private </font>

I cannot reach the internet from private but from all other networks without any problems. I can also reach the complete 100.0.0.0 network from the private network but not the internet.
Reply With Quote
  #9 (permalink)  
Old 01-15-2004, 12:21 PM
AJo AJo is offline
Senior Member
 
Join Date: Mar 2002
Location: sweden
Posts: 140
Default Re: Problems with network configuration

myself:

Well that gave a better picture =)

The MASQ rule looks odd. Looks like you are MASQ the private network as if it came from the private network, what is the same as not doing a MASQ at all.

The MASQ should look something like.
Rule type: masq
Network: private_network__
Interface: gateway_interface__ (ie. 99.0.0.2)
Reply With Quote
  #10 (permalink)  
Old 01-16-2004, 09:03 AM
Junior Member
 
Join Date: Sep 2003
Posts: 15
Default Re: Problems with network configuration

[ QUOTE ]


Interface: gateway_interface__ (ie. 99.0.0.2)


[/ QUOTE ]

Yeah, thats it! Thanks a lot for helping !
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 08:35 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.