Need HELP with Red Hat Linux 9 iptables firewall/router

From: Aleksandr Zingorenko (azingorenko_at_ucdavis.edu)
Date: 07/11/03


Date: Thu, 10 Jul 2003 17:08:59 -0700

I am having a problem with a firewall that is simply too strict.
Specifically, I am trying to configure an iptables firewall on Red Hat Linux
9 that protects the servers on our Windows 2000 network from hacker/cracker
attacks. So far, I have 2 Win2k machines behind this firewall, and each of
them has a private IP address. In addition, I configured the firewall to
use DNAT to map valid IP addresses to private ones for those two machines.
As a result, each machine can connect to the Internet and reach (ping) any
other machine on our network, behind the firewall or not. However, whenever
any machine NOT behind the firewall tries to reach any of these 2 machines,
it fails (the farthest a successful ping can go at this point is the
firewall's external interface) even though the policy of every chain in
every table is ACCEPT and only SNAT and DNAT rules are specified. Can
anyone tell me how I could fix this problem? I realize that a firewall
should keep "outsiders" out, but we have servers that we want to protect
from malicious code and yet allow employees in our department limited access
to them.



Relevant Pages

  • Re: Norton 2005 Int Security, Trend PCcillin or Zone Alarm ???????
    ... > I want security I can run on both machines. ... System overhead is higher than standard firewall applications. ... Symantec products do not remove (uninstall) well. ... Micro Trends PC-Cillan is very good (possibly the best in home network ...
    (alt.computer.security)
  • Re: Setting Up A WorkGroup for file and Share Printing
    ... Tried that amd could access only one of the two drives, the D drive, however ... I Turned off NIS 2008 firewall ... I made sure the Registry setting "IRPStackSize" on both machines ... Here are general network troubleshooting steps. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Is there a simple published solution?
    ... You need to set up file/printer sharing on both the computers in order to ... Here are general network ... start by running the Network Setup Wizard on all machines (see ... by 1) a misconfigured firewall or overlooked firewall (including a stateful ...
    (microsoft.public.windows.vista.networking_sharing)
  • Re: Shared Printer Problem
    ... "Printer status cannot be displayed with port that is currently running." ... file/printer sharing and then install the correct drivers for your printer ... start by running the Network Setup Wizard on all machines (see ... by 1) a misconfigured firewall or overlooked firewall (including a stateful ...
    (microsoft.public.windows.vista.print_fax_scan)
  • Re: Can find Vista box, cant share folders or printers.
    ... When I click 'Network' on the laptop the ... I've disabled Norton and Windows firewall entirely to make sure that's not ... public folder sharing - on ... start by running the Network Setup Wizard on all machines (see ...
    (microsoft.public.windows.vista.networking_sharing)