Professional Web Applications Themes

Does IPFILER from TLS709 work with one NIC with multiple IP addresses? - SCO

I have tried to install ipfilter on OSR504 using configuration below: map net0 0.0.0.0/0 -> 0.0.0.0/32 proxy port ftp ftp/tcp map net0 193.88.1.0/24 -> 0.0.0.0/32 proxy port ftp ftp/tcp map net0 193.88.1.0/24 -> 0.0.0.0/32 portmap tcp/udp 10000:40000 map net0 193.88.1.0/24 -> 0.0.0.0/32 /etc/default/inet: ipforwarding 1 ipsendredirects 1 /etc/ipf.conf: pass out all 192.168.0.1 193.88.1.4 -> 193.88.1.1 -> Outside World 202.197.2.24 "A" "B" I can ping both 193.88.1.1 and 202.197.2.24 but I could not ping the "Outside World" from 193.88.1.4. Does it mean that IPFILTER isn't working with one NIC or I need true private IP interface to have it working i.e. ...

  1. #1

    Default Does IPFILER from TLS709 work with one NIC with multiple IP addresses?

    I have tried to install ipfilter on OSR504 using configuration below:

    map net0 0.0.0.0/0 -> 0.0.0.0/32 proxy port ftp ftp/tcp
    map net0 193.88.1.0/24 -> 0.0.0.0/32 proxy port ftp ftp/tcp
    map net0 193.88.1.0/24 -> 0.0.0.0/32 portmap tcp/udp 10000:40000
    map net0 193.88.1.0/24 -> 0.0.0.0/32

    /etc/default/inet:
    ipforwarding 1
    ipsendredirects 1

    /etc/ipf.conf:
    pass out all

    192.168.0.1
    193.88.1.4 -> 193.88.1.1 -> Outside World
    202.197.2.24
    "A" "B"


    I can ping both 193.88.1.1 and 202.197.2.24 but I could not ping the
    "Outside World" from 193.88.1.4.

    Does it mean that IPFILTER isn't working with one NIC or I need true
    private IP interface to have it working i.e. 192.168.0.1 instead of
    193.88.1.1.

    Thanks,
    Chalawal
    Chalawal Maliwan Guest

  2. #2

    Default Re: Does IPFILER from TLS709 work with one NIC with multiple IP addresses?

    Chalawal Maliwan typed (on Wed, Jul 23, 2003 at 11:40:12PM -0700):
    | I have tried to install ipfilter on OSR504 using configuration below:
    |
    | map net0 0.0.0.0/0 -> 0.0.0.0/32 proxy port ftp ftp/tcp
    | map net0 193.88.1.0/24 -> 0.0.0.0/32 proxy port ftp ftp/tcp
    | map net0 193.88.1.0/24 -> 0.0.0.0/32 portmap tcp/udp 10000:40000
    | map net0 193.88.1.0/24 -> 0.0.0.0/32
    |
    | /etc/default/inet:
    | ipforwarding 1
    | ipsendredirects 1
    |
    | /etc/ipf.conf:
    | pass out all
    |
    | 192.168.0.1
    | 193.88.1.4 -> 193.88.1.1 -> Outside World
    | 202.197.2.24
    | "A" "B"
    |
    |
    | I can ping both 193.88.1.1 and 202.197.2.24 but I could not ping the
    | "Outside World" from 193.88.1.4.
    |
    | Does it mean that IPFILTER isn't working with one NIC or I need true
    | private IP interface to have it working i.e. 192.168.0.1 instead of
    | 193.88.1.1.
    |

    I'm using 198.207.210 for my NAT'ed addresses, so that's not your
    problem. My ipnat.rules file contains:

    map net1 198.207.210.0/24 -> 66.167.21.66/32

    This is NOT the filter rules file, and it's run by ipnat, as opposed to
    my ipf.conf file which is run by ipfilter.


    --
    JP
    Jean-Pierre Radley Guest

  3. #3

    Default Re: Does IPFILER from TLS709 work with one NIC with multiple IP addresses?

    >
    > I'm using 198.207.210 for my NAT'ed addresses, so that's not your
    > problem. My ipnat.rules file contains:
    >
    > map net1 198.207.210.0/24 -> 66.167.21.66/32
    >
    > This is NOT the filter rules file, and it's run by ipnat, as opposed to
    > my ipf.conf file which is run by ipfilter.
    I have it running now by changing the 202.197.2.24 from alias to the
    real IP address. I can ping, telnet and etc. to the outside world but
    not traceroute.
    Do I need to run "routed" on the "202.197.2.24" to have traceroute to
    work.

    Thanks,

    Chalawal
    Chalawal Maliwan Guest

  4. #4

    Default Re: Does IPFILER from TLS709 work with one NIC with multiple IP addresses?

    Below please find more about findings:

    "B" can telnet to 193.88.1.x only if the default route on
    193.88.1.x is set to 193.88.1.1
    While telneting to 193.88.1.4 from "B", 193.88.1.4 sees "B" as
    coming from 202.197.2.24

    I must be missing something here. Can anyone please suggest?

    Thanks,
    chalawal
    Chalawal Maliwan Guest

Similar Threads

  1. Multiple Debugging IP addresses
    By HairyDude in forum Coldfusion Server Administration
    Replies: 0
    Last Post: August 5th, 02:11 PM
  2. Multiple Debugging IP addresses
    By covretro in forum Coldfusion Server Administration
    Replies: 0
    Last Post: August 5th, 12:22 PM
  3. Multiple IP Addresses For Same Host in /etc/hosts
    By Tennis Smith in forum Linux / Unix Administration
    Replies: 1
    Last Post: December 9th, 10:15 PM
  4. Sending mail to multiple addresses
    By René de Leeuw in forum ASP.NET General
    Replies: 0
    Last Post: July 22nd, 03:35 PM
  5. Mac addresses / Multiple airports
    By Bobby Janow in forum Mac Applications & Software
    Replies: 11
    Last Post: July 9th, 02:40 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139