Dieser Beitrag wurde bereits 1 mal editiert, zuletzt von »Regidür« (21.06.2011, 16:59)
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 |
# Generated by iptables-save v1.4.10 on Fri Mar 4 13:39:00 2011 nat :PREROUTING ACCEPT [2092:177065] :INPUT ACCEPT [1104:95060] :OUTPUT ACCEPT [606:89067] :POSTROUTING ACCEPT [830:109600] COMMIT # Completed on Fri Mar 4 13:39:00 2011 # Generated by iptables-save v1.4.10 on Fri Mar 4 13:39:00 2011 *mangle :PREROUTING ACCEPT [3953561:4306229783] :INPUT ACCEPT [3950403:4305919633] :FORWARD ACCEPT [3145:308867] :OUTPUT ACCEPT [3773367:3410361600] :POSTROUTING ACCEPT [3776390:3410773082] COMMIT # Completed on Fri Mar 4 13:39:00 2011 # Generated by iptables-save v1.4.10 on Fri Mar 4 13:39:00 2011 *filter :INPUT ACCEPT [1080:178599] :FORWARD DROP [0:0] :OUTPUT ACCEPT [3758328:3408648723] -A INPUT -i Io -j ACCEPT -A INPUT -i eth0 -j ACCEPT -A INPUT ! -i eth0 -p udp -m udp --dport 67 -j REJECT --reject-with icmp-port-unreachable -A INPUT ! -i eth0 -p udp -m udp --dport 53 -j REJECT --reject-with icmp-port-unreachable -A INPUT ! -i eth0 -p udp -m udp --dport 0:1023 -j DROP -A INPUT ! -i eth0 -p tcp -m tcp --dport 0:1023 -j DROP -A FORWARD -d 192.168.0.0/16 -i eth0 -j DROP -A FORWARD -s 192.168.0.0/16 -i eth0 -j ACCEPT -A FORWARD -d 192.168.0.0/16 -i ppp0 -j ACCEPT COMMIT # Completed on Fri Mar 4 13:39:00 2011 |
Quellcode |
|
1 2 |
:POSTROUTING ACCEPT [3829:258890] -A POSTROUTING -o ppp0 -j MASQUERADE |
Quellcode |
|
1 |
iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE |
Quellcode |
|
1 2 |
cat /proc/sys/net/ipv4/ip_forward # sollte 1 sein, sonst echo 1 > /proc/sys/net/ipv4/ip_forward |
Quellcode |
|
1 |
net.ipv4.ip_forward = 1 |
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 |
EG-Server ~ # iptables -vL Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 294 28756 ACCEPT all -- lo any anywhere anywhere 6789 564K ACCEPT all -- eth0 any anywhere anywhere 0 0 REJECT udp -- !eth0 any anywhere anywhere udp dpt:bootps reject-with icmp-port-unreachable 0 0 REJECT udp -- !eth0 any anywhere anywhere udp dpt:domain reject-with icmp-port-unreachable 0 0 DROP tcp -- !eth0 any anywhere anywhere tcp dpts:0:1023 0 0 DROP udp -- !eth0 any anywhere anywhere udp dpts:0:1023 Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 DROP all -- eth0 any anywhere 192.168.0.0/16 0 0 ACCEPT all -- eth0 any 192.168.0.0/16 anywhere 0 0 ACCEPT all -- ppp0 any anywhere 192.168.0.0/16 Chain OUTPUT (policy ACCEPT 2585 packets, 963K bytes) pkts bytes target prot opt in out source destination |
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 |
EG-Server ~ # iptables -t nat -vL Chain PREROUTING (policy ACCEPT 36 packets, 4928 bytes) pkts bytes target prot opt in out source destination Chain INPUT (policy ACCEPT 36 packets, 4928 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 344 packets, 25919 bytes) pkts bytes target prot opt in out source destination Chain POSTROUTING (policy ACCEPT 304 packets, 23119 bytes) pkts bytes target prot opt in out source destination 40 2800 MASQUERADE all -- any ppp0 anywhere anywhere |
Quellcode |
|
1 |
route -n |
Quellcode |
|
1 2 3 4 5 6 |
CONNECT --> Carrier detected. Starting PPP immediately. --> Starting pppd at Mon Jun 20 15:12:14 2011 --> Pid of pppd: 2271 --> Using interface ppp0 --> local IP address 10.50.204.228 |
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 |
Lummerland ~ # ping -c3 192.168.0.76 PING 192.168.0.76 (192.168.0.76) 56(84) bytes of data. 64 bytes from 192.168.0.76: icmp_req=1 ttl=64 time=0.999 ms 64 bytes from 192.168.0.76: icmp_req=2 ttl=64 time=0.181 ms 64 bytes from 192.168.0.76: icmp_req=3 ttl=64 time=0.183 ms --- 192.168.0.76 ping statistics --- 3 packets transmitted, 3 received, 0% packet loss, time 2003ms rtt min/avg/max/mdev = 0.181/0.454/0.999/0.385 ms Lummerland ~ # route -n Kernel IP Routentabelle Ziel Router Genmask Flags Metric Ref Use Iface 192.168.0.0 0.0.0.0 255.255.255.0 U 202 0 0 eth0 127.0.0.0 127.0.0.1 255.0.0.0 UG 0 0 0 lo 0.0.0.0 192.168.0.76 0.0.0.0 UG 2 0 0 eth0 Lummerland ~ # ping 10.50.204.228 PING 10.50.204.228 (10.50.204.228) 56(84) bytes of data. 64 bytes from 10.50.204.228: icmp_req=1 ttl=64 time=0.192 ms 64 bytes from 10.50.204.228: icmp_req=2 ttl=64 time=0.192 ms 64 bytes from 10.50.204.228: icmp_req=3 ttl=64 time=0.183 ms 64 bytes from 10.50.204.228: icmp_req=4 ttl=64 time=0.175 ms 64 bytes from 10.50.204.228: icmp_req=5 ttl=64 time=0.183 ms 64 bytes from 10.50.204.228: icmp_req=6 ttl=64 time=0.178 ms 64 bytes from 10.50.204.228: icmp_req=7 ttl=64 time=0.197 ms ^C --- 10.50.204.228 ping statistics --- 7 packets transmitted, 7 received, 0% packet loss, time 5999ms rtt min/avg/max/mdev = 0.175/0.185/0.197/0.017 ms |
Quellcode |
|
1 2 3 |
# Generated by net-scripts for interface eth0 nameserver 193.189.244.225 nameserver 193.189.244.206 |
Quellcode |
|
1 |
dns_servers_eth0="193.189.244.225 193.189.244.206" |
Quellcode |
|
1 2 3 4 |
Router (192.168.0.1) ------- Switch ------ Homeserver (192.168.0.76) |----------Laptop (Wlan) |------Client 2 |-----------Client 1 '------Client 3 '-----------Hausdrucker |
Ich hoffe, Du hast die DNS-Server auf den Clients eingetragen und nicht auf dem Server. An sonsten fällt mir nichts ein, warum es nicht funktionieren sollte.Mit dem testweisen Eintrage der DNS-Adressen in die /etc/resolv.conf hat die Auflösung nicht funktioniert!
Quellcode |
|
1 |
eix -C firewall -S iptables |
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 |
eth0 Link encap:Ethernet HWaddr bc:ae:c5:18:d0:47 inet addr:192.168.0.76 Bcast:192.168.0.255 Mask:255.255.255.0 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:8238 errors:0 dropped:0 overruns:0 frame:0 TX packets:14326 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:935069 (913.1 KiB) TX bytes:1695006 (1.6 MiB) Interrupt:40 lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:397 errors:0 dropped:0 overruns:0 frame:0 TX packets:397 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:37720 (36.8 KiB) TX bytes:37720 (36.8 KiB) ppp0 Link encap:Point-to-Point Protocol inet addr:10.173.49.181 P-t-P:10.64.64.64 Mask:255.255.255.255 UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1 RX packets:55 errors:0 dropped:0 overruns:0 frame:0 TX packets:55 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:3 RX bytes:4646 (4.5 KiB) TX bytes:3675 (3.5 KiB) |
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 |
Chain PREROUTING (policy ACCEPT 369 packets, 24204 bytes) pkts bytes target prot opt in out source destination Chain INPUT (policy ACCEPT 41 packets, 2980 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 52 packets, 4819 bytes) pkts bytes target prot opt in out source destination Chain POSTROUTING (policy ACCEPT 8 packets, 1548 bytes) pkts bytes target prot opt in out source destination 44 3271 MASQUERADE all -- any ppp0 anywhere anywhere |
Quellcode |
|
1 2 3 4 5 |
#config_eth0=( "dhcp" ) config_eth0=( "192.168.0.76 broadcast 192.168.0.255 netmask 255.255.255.0" ) #routes_eth0=( "default gw 192.168.0.1" ) #dns_servers_eth0=( "192.168.0.1" ) ifdown_eth0=NO |
Quellcode |
|
1 2 3 |
# Generated by net-scripts for interface eth0 nameserver 193.189.244.225 nameserver 193.189.244.206 |
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 |
eth0 Protokoll:Ethernet Hardware Adresse 00:e0:18:f6:c8:e7 inet Adresse:192.168.0.136 Bcast:192.168.0.255 Maske:255.255.255.0 inet6 Adresse: fe80::2e0:18ff:fef6:c8e7/64 Gültigkeitsbereich:Verbindung UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:53169 errors:0 dropped:0 overruns:0 frame:0 TX packets:43043 errors:0 dropped:0 overruns:0 carrier:0 Kollisionen:0 Sendewarteschlangenlänge:1000 RX bytes:6603476 (6.2 MiB) TX bytes:4402371 (4.1 MiB) Interrupt:10 lo Protokoll:Lokale Schleife inet Adresse:127.0.0.1 Maske:255.0.0.0 inet6 Adresse: ::1/128 Gültigkeitsbereich:Maschine UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:399 errors:0 dropped:0 overruns:0 frame:0 TX packets:399 errors:0 dropped:0 overruns:0 carrier:0 Kollisionen:0 Sendewarteschlangenlänge:0 RX bytes:46401 (45.3 KiB) TX bytes:46401 (45.3 KiB) sit0 Protokoll:IPv6-nach-IPv4 inet6 Adresse: ::127.0.0.1/96 Gültigkeitsbereich:Unbekannt inet6 Adresse: ::192.168.0.136/96 Gültigkeitsbereich:Kompatibilität UP RUNNING NOARP MTU:1480 Metric:1 RX packets:0 errors:0 dropped:0 overruns:0 frame:0 TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 Kollisionen:0 Sendewarteschlangenlänge:0 RX bytes:0 (0.0 B) TX bytes:0 (0.0 B) |
Quellcode |
|
1 2 3 4 5 |
#config_eth0=( "dhcp" ) config_eth0=( "192.168.0.136/24" ) ifdown_eth0="no" routes_eth0=( "default gw 192.168.0.76" ) dns_servers_eth0="193.189.244.225 193.189.244.206" |
Quellcode |
|
1 2 3 |
# Generated by net-scripts for interface eth0 nameserver 193.189.244.225 nameserver 193.189.244.206 |
Quellcode |
|
1 |
tail -f /var/log/messages |
Dieser Beitrag wurde bereits 1 mal editiert, zuletzt von »Regidür« (21.06.2011, 11:31)
Quellcode |
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 |
iptables -A INPUT -m state --state INVALID -j LOG --log-prefix "INV_INP:" iptables -A FORWARD -m state --state INVALID -j LOG --log-prefix "INV_FWD:" iptables -A OUTPUT -m state --state INVALID -j LOG --log-prefix "INV_OUT:" iptables -t nat -A POSTROUTING -m state --state INVALID -j LOG --log-prefix "INV_SNAT:" iptables -t nat -A PREROUTING -m state --state INVALID -j LOG --log-prefix "INV_DNAT:" iptables -A INPUT -p tcp --dport 53 -j LOG --log-prefix "D_TCP_INP:" iptables -A FORWARD -p tcp --dport 53 -j LOG --log-prefix "D_TCP_FWD:" iptables -A OUTPUT -p tcp --dport 53 -j LOG --log-prefix "D_TCP_OUT:" iptables -t nat -p tcp --dport 53 -A POSTROUTING -j LOG --log-prefix "D_TCP_SNAT:" iptables -t nat -p tcp --dport 53 -A PREROUTING -j LOG --log-prefix "D_TCP_DNAT:" iptables -A INPUT -p udp --dport 53 -j LOG --log-prefix "D_UDP_INP:" iptables -A FORWARD -p udp --dport 53 -j LOG --log-prefix "D_UDP_FWD:" iptables -A OUTPUT -p udp --dport 53 -j LOG --log-prefix "D_UDP_OUT:" iptables -t nat -p udp --sport 53 -A POSTROUTING -j LOG --log-prefix "D_UDP_SNAT:" iptables -t nat -p udp --sport 53 -A PREROUTING -j LOG --log-prefix "D_UDP_DNAT:" iptables -A INPUT -p tcp --sport 53 -j LOG --log-prefix "S_TCP_INP:" iptables -A FORWARD -p tcp --sport 53 -j LOG --log-prefix "S_TCP_FWD:" iptables -A OUTPUT -p tcp --sport 53 -j LOG --log-prefix "S_TCP_OUT:" iptables -t nat -p tcp --sport 53 -A POSTROUTING -j LOG --log-prefix "S_TCP_SNAT:" iptables -t nat -p tcp --sport 53 -A PREROUTING -j LOG --log-prefix "S_TCP_DNAT:" iptables -A INPUT -p udp --sport 53 -j LOG --log-prefix "S_UDP_INP:" iptables -A FORWARD -p udp --sport 53 -j LOG --log-prefix "S_UDP_FWD:" iptables -A OUTPUT -p udp --sport 53 -j LOG --log-prefix "S_UDP_OUT:" iptables -t nat -p udp --sport 53 -A POSTROUTING -j LOG --log-prefix "S_UDP_SNAT:" iptables -t nat -p udp --sport 53 -A PREROUTING -j LOG --log-prefix "S_UDP_DNAT:" |