Re: NAT Traversal

From: /dev/null (dev'0x2e'null@BeginThread.com)
Date: 12/11/02


From: "/dev/null" <dev'0x2e'null@BeginThread.com>
Date: Wed, 11 Dec 2002 14:51:36 GMT


> The only conclusion I've been able to come up with, and this is from
tailing
> log files while trying to transfer files, is that iptables is dropping the
> packets from the other end because it's somehow "seeing" the other side's
> internal ip address.

Then the problem would have to be on their end. Your iptables wouldn't know
how to route to someone else's internal IP address, nor would any other
router along the way. Just like you have to do a S-NAT on outbound traffic,
so do they. If they don't, there's nothing you can do about it.



Relevant Pages

  • RE: How can I get all IP transactions (in/out) logged?
    ... I am pretty sure freshmeat.net has a tool that uses iptables and puts it into a mysql database...try looking under "monitor" or "uptime" its there somewhere. ... With syslog logging, you will also probably want to look into a syslog ... #2 logs packets out ppp0 sourced from the router/host machine ... > in any of the system log files). ...
    (Debian-User)
  • Re: log files
    ... Can you tell me who can i make log files? ... I want to make log file of iptables? ... rule will be display in ACCEPT chain. ... Electronic Mail is not secure, may not be read every day, and should not ...
    (RedHat)
  • [opensuse] Re: dictionary attacks
    ... I'll vote for this too, although I would like to get something that uses iptables instead - taking the load off sshd. ... It works for several log files, ... It only falls short when the ssh-login host is in a DMZ, the logs are actually stored and processed on a different host, and the firewall is a 3rd system. ...
    (SuSE)
  • Re: How to react to "authentication failures" in log file
    ... Maybe even flush iptables periodically to keep ... IPS systems for intrustion prevention are basically an intrusion ... open source options, including denyhost. ... One can configure which log files to scan, ...
    (comp.security.ssh)
  • Re: Question on Internet access of vsftp server
    ... I've been editing the iptables by hand. ... configuration tool that I was using didn't handle the firewall rules ... of the log files in /var/log. ... I've tested FTP from this machine to a .gov server that I ...
    (RedHat)

Quantcast