Networking Forums

Networking Forums > Computer Networking > Linux Networking > ip forwarding woes

Reply
Thread Tools Display Modes

ip forwarding woes

 
 
David Zelinsky
Guest
Posts: n/a

 
      03-08-2008, 08:16 PM
I'm trying to set up a firewall/gateway, and I can't seem to get
ip forwarding to work. I'm using linux kernel 2.6.23 with iptables
enabled. Here's what happens.

The firewall machine has two interfaces (both on private networks, for
testing purposes):

IF IP Netmask
eth0 192.168.0.1 255.255.255.0
eth1 10.0.0.1 255.255.255.0

This is the routing table:

Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
10.0.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1

I enable IP forwarding, with 'echo 1 >/proc/sys/net/ipv4/ip_forward'

I have the iptables_* modules loaded (* = forward,nat,mangle,raw).
There are no rules in any of the tables, but all have ACCEPT as the
default policy.

I have two other machines, one at 192.168.0.2 (connected to the same
hub as firewall's eth0) and one at 10.0.0.2 (connected via crossover
to firewall's eth1).

From the firewall, I can ping both the other hosts.
From either host, I can ping the firewall at both 192.160.0.1 and 10.0.0.1.

With this setup, I expect to be able to ping 10.0.0.2 from 192.168.0.2
(and vice versa), with packets routed through the firewall, but it
doesn't work.

What am I overlooking?

I did try putting explicit iptables rules in the FILTER chain of the
forward table, but it didn't make any difference.

Any suggestions would be much appreciated.

--
David Zelinsky

 
Reply With Quote
 
 
 
 
David Zelinsky
Guest
Posts: n/a

 
      03-08-2008, 09:18 PM
Never mind, I found my mistake. The routing table of one of the hosts
was not exactly as described below, and was causing return packets to be
lost. I made the configuration actually agree with what I described and
now it works. Sorry to bother people.

David Zelinsky wrote:
> I'm trying to set up a firewall/gateway, and I can't seem to get
> ip forwarding to work. I'm using linux kernel 2.6.23 with iptables
> enabled. Here's what happens.
>
> The firewall machine has two interfaces (both on private networks, for
> testing purposes):
>
> IF IP Netmask
> eth0 192.168.0.1 255.255.255.0
> eth1 10.0.0.1 255.255.255.0
>
> This is the routing table:
>
> Destination Gateway Genmask Flags Metric Ref Use Iface
> 192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
> 10.0.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
>
> I enable IP forwarding, with 'echo 1 >/proc/sys/net/ipv4/ip_forward'
>
> I have the iptables_* modules loaded (* = forward,nat,mangle,raw).
> There are no rules in any of the tables, but all have ACCEPT as the
> default policy.
>
> I have two other machines, one at 192.168.0.2 (connected to the same
> hub as firewall's eth0) and one at 10.0.0.2 (connected via crossover
> to firewall's eth1).
>
> From the firewall, I can ping both the other hosts.
> From either host, I can ping the firewall at both 192.160.0.1 and 10.0.0.1.
>
> With this setup, I expect to be able to ping 10.0.0.2 from 192.168.0.2
> (and vice versa), with packets routed through the firewall, but it
> doesn't work.
>
> What am I overlooking?
>
> I did try putting explicit iptables rules in the FILTER chain of the
> forward table, but it didn't make any difference.
>
> Any suggestions would be much appreciated.
>

 
Reply With Quote
 
Ilario
Guest
Posts: n/a

 
      04-15-2008, 04:30 PM
Could you write down your configuration? It's exactly the problem I'm
trying to solve.. thanks a lot!
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
port forwarding woes lorenz117@hotmail.com Windows Networking 0 06-30-2006 01:59 PM
gah! VPN woes! ComPCs Home Networking 0 07-25-2005 09:58 PM
LAN woes pheasant Wireless Internet 12 01-17-2005 04:49 AM
IIS Woes Bri Broadband Hardware 1 07-08-2004 05:10 AM
MN700 Port Forwarding Woes Veraxus Broadband Hardware 5 06-15-2004 06:18 AM



1 2 3 4 5 6 7 8 9 10 11