There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming google gpu hard drive hardware hdmi internet laptop malware memory missing monitor motherboard network operating system printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Strange IPchains / Network Issue

Reply  
Thread Tools
rags_sys's Avatar
Junior Member with 2 posts.
 
Join Date: Aug 2004
Experience: Advanced
06-Aug-2004, 04:38 AM #1
Strange IPchains / Network Issue
Hi Guys,
Two networks - 10.0.0.0/8 & 192.168.1.0/24 connected through VPN - GRE Tunnel. Machines of one network can ping the other network. Ipchains Firewall gateway 10.0.0.5 in 10.0.0.0 network. Proxy Squid running on 3128 on 10.0.0.5.


Route for 10.* subnet to 192.168.1.* is 10.0.0.1
Rule for 10.* network in ipchains to access proxy 10.0.0.5

/sbin/ipchains -A input -i eth1 -s 10.0.0.0/255.0.0.0 -d 10.0.0.5 3128 -p tcp -j ACCEPT
/sbin/ipchains -A output -i eth1 -s 10.0.0.5 3128 -d 10.0.0.0/255.0.0.0 ! -y -p tcp -j ACCEPT

Route for 192.168.1.* subnet's gateway is 192.168.1.2 and all machines are configured with this one.
Rule for 192.* network in ipchains to access proxy 3128 in 10.0.0.5

/sbin/ipchains -A input -i eth1 -s 192.168.1.0/255.255.255.0 -d 10.0.0.5 3128 -p tcp -l -j ACCEPT
/sbin/ipchains -A output -i eth1 -s 10.0.0.5 3128 -d 192.168.1.0/255.255.255.0 ! -y -p tcp -l -j ACCEPT


Problem is that only one machine (Lets says abc machine IP - 192.168.1.1) from that network is able to browse the internet. None of the other machines 192.168.1.3, 192.168.1.4 etc are not able to browse. If 192.168.1.1 IP is given for any other machine then, that machine is not able to browse. If ABC machine is given 192.168.1.34 then it is able to browse.

One mre thing is that If I remove the firewall, then all machines with appropriate Squid ACLs are able to browse.

My Redhat Linux is 6.2 Zoot and Kernel is 2.2.14-5.0.

How do we solve the problem. Route and reverse route for both networks are working perfectly. All machines in 192.168.1.* is able to ping gateway 192.168.1.2 and 10.0.0.5 (10.*) and Vice Versa.

Thanks,
Raghavan.S
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 09:49 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.