Ik heb net M0n0wall als firewall/NAT-router geinstalleerd, opt1 heb ik naar DMZ veranderd, op de DMZ zit een ftp-/ http-/ smtp- server, echter kan ik deze niet bereiken vanuit LAN-subnet en ook niet vanaf WAN. Ik kan ook niet de server-ip in DMZ pingen
Ik heb het volgende gedaan;
Proto Ext. port range NAT IP
(ext. IP) Int. port range Description
TCP 25 (SMTP) 192.168.131.130 25 (SMTP) SMTP forwarded to Clarkconnect server
TCP 80 (HTTP) 192.168.131.130 80 (HTTP) HTTP forwarded to Clarkconnect server
TCP/UDP 21 (FTP) 192.168.131.130 21 (FTP) FTP forwarded to Clarkconnect server
Nu wordt automatisch firewall rules aangemaakt door m0n0wall
EDITJE
Ik snap er niet van opeens stopt m0n0wall met routeren, kan niet DMZ gateway meer pingen, kan niet de WAN-interface meer pingen alleen nog maar LAN-gateway. Volgens settings is WAN up;
Heb wat logfiles hier van systems settiings en van de Syslog-client:
Bootlog; Last 50 system log entries
Apr 2 19:10:51 /kernel: vx0: <3COM 3C595 Fast Etherlink III PCI> port 0xe400-0xe41f irq 12 at device 11.0 on pci0
Apr 2 19:10:51 /kernel: [*mii*]: disable 'auto select' with DOS util! address 00:a0:24:9d:96:08
Apr 2 19:10:51 /kernel: vx0: driver is using old-style compatibility shims
Apr 2 19:10:51 /kernel: xl0: <3Com 3c905B-TX Fast Etherlink XL> port 0xe800-0xe87f mem 0xec001000-0xec00107f irq 10 at device 13.0 on pci0
Apr 2 19:10:51 /kernel: xl0: Ethernet address: 00:10:4b:7b:69:05
Apr 2 19:10:51 /kernel: miibus0: <MII bus> on xl0
Apr 2 19:10:51 /kernel: xlphy0: <3Com internal media interface> on miibus0
Apr 2 19:10:51 /kernel: xlphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
Apr 2 19:10:51 /kernel: xl1: <3Com 3c900B-TPO Etherlink XL> port 0xec00-0xec7f mem 0xec000000-0xec00007f irq 11 at device 15.0 on pci0
Apr 2 19:10:51 /kernel: xl1: Ethernet address: 00:50:da:d0:e7:09
Apr 2 19:10:51 /kernel: xl1: selecting 10baseT transceiver, half duplex
Apr 2 19:10:51 /kernel: orm0: <Option ROM> at iomem 0xc0000-0xc7fff on isa0
Apr 2 19:10:51 /kernel: pmtimer0 on isa0
Apr 2 19:10:51 /kernel: fdc0: <NEC 72065B or clone> at port 0x3f0-0x3f5,0x3f7 irq 6 drq 2 on isa0
Apr 2 19:10:51 /kernel: fdc0: FIFO enabled, 8 bytes threshold
Apr 2 19:10:51 /kernel: fd0: <1440-KB 3.5" drive> on fdc0 drive 0
Apr 2 19:10:51 /kernel: atkbdc0: <Keyboard controller (i8042)> at port 0x60,0x64 on isa0
Apr 2 19:10:51 /kernel: vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
Apr 2 19:10:51 /kernel: sc0: <System console> at flags 0x100 on isa0
Apr 2 19:10:51 /kernel: sc0: VGA <16 virtual consoles, flags=0x300>
Apr 2 19:10:51 /kernel: sio0 at port 0x3f8-0x3ff irq 4 flags 0x10 on isa0
Apr 2 19:10:51 /kernel: sio0: type 16550A
Apr 2 19:10:51 /kernel: sio1: configured irq 3 not in bitmap of probed irqs 0
Apr 2 19:10:51 /kernel: BRIDGE 020214 loaded
Apr 2 19:10:51 /kernel: IPsec: Initialized Security Association Processing.
Apr 2 19:10:51 /kernel: IP Filter: v3.4.31 initialized. Default = block all, Logging = enabled
Apr 2 19:10:51 /kernel: acd0: CDROM <TOSHIBA CD-ROM XM-6002B> at ata1-master PIO3
Apr 2 19:10:51 /kernel: Mounting root from ufs:/dev/md0c
Apr 2 19:10:51 /kernel: vx0: warning: strange connector type in EEPROM.
Apr 2 19:10:51 /kernel: vx0: selected utp. (forced)
Apr 2 19:10:52 dnsmasq[74]: started, version 1.18 cachesize 150
Apr 2 19:10:52 dnsmasq[74]: read /etc/hosts - 4 addresses
Apr 2 19:10:52 dhcpd: Internet Software Consortium DHCP Server V3.0.1rc11
Apr 2 19:10:52 dnsmasq[74]: reading /etc/resolv.conf
Apr 2 19:10:52 dhcpd: Copyright 1995-2003 Internet Software Consortium.
Apr 2 19:10:52 dnsmasq[74]: using nameserver 212.142.9.50#53
Apr 2 19:10:52 dhcpd: All rights reserved.
Apr 2 19:10:52 dnsmasq[74]: using nameserver 212.142.28.66#53
Apr 2 19:10:52 dhcpd: For info, please visit
http://www.isc.org/products/DHCP
Apr 2 19:10:54 dhclient: DHCPDISCOVER on xl1 to 255.255.255.255 port 67 interval 8
Apr 2 19:10:54 dhclient: DHCPOFFER from 10.98.128.1
Apr 2 19:10:54 dhclient: DHCPREQUEST on xl1 to 255.255.255.255 port 67
Apr 2 19:10:54 dhclient: DHCPACK from 10.98.128.1
Apr 2 19:10:54 dhclient: New Network Number: 80.57.56.0
Apr 2 19:10:54 dhclient: New Broadcast Address: 255.255.255.255
Apr 2 19:10:54 dhclient: New IP Address (xl1): 80.57.56.3
Apr 2 19:10:54 dhclient: New Subnet Mask (xl1): 255.255.254.0
Apr 2 19:10:54 dhclient: New Broadcast Address (xl1): 255.255.255.255
Apr 2 19:10:54 dhclient: New Routers: 80.57.56.1
Apr 2 19:10:56 dhclient: bound to 80.57.56.3 -- renewal in 212563 seconds.
Syslog;
04-02-2004 19:03:03 Local0.Warning 192.168.130.129 Apr 2 19:02:50 ipmon[61]: 19:02:50.318506 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
04-02-2004 19:02:59 Local0.Warning 192.168.130.129 Apr 2 19:02:46 ipmon[61]: 19:02:46.317504 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
04-02-2004 19:02:57 Local0.Warning 192.168.130.129 Apr 2 19:02:44 ipmon[61]: 19:02:44.316992 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
04-02-2004 19:02:56 Local0.Warning 192.168.130.129 Apr 2 19:02:43 ipmon[61]: 19:02:43.316752 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
04-02-2004 19:02:55 Local0.Warning 192.168.130.129 Apr 2 19:02:42 ipmon[61]: 19:02:42.317406 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
04-02-2004 19:02:49 Local0.Warning 192.168.130.129 Apr 2 19:02:36 ipmon[61]: 19:02:35.967833 xl0 @0:18 b 192.168.130.137,1305 -> 131.174.93.58,25 PR tcp len 20 48 -S IN
04-02-2004 19:02:47 Local0.Warning 192.168.130.129 Apr 2 19:02:35 ipmon[61]: 19:02:35.312751 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
04-02-2004 19:02:43 Local0.Warning 192.168.130.129 Apr 2 19:02:31 ipmon[61]: 19:02:31.311745 xl0 @0:18 b 192.168.130.137,1041 -> 212.142.28.66,53 PR udp len 20 66 IN
Maar goed dat ik Ipcop op de HD van server heb draaien, ff inpluggen, boot sequence veranderen en kan weer het net op.
OK, wat gaat er fout BSD-whizkids?
Nog een EDITJE;
Mischien is het makkelijk, voor mij en ook andere, om het DMZ portworwarding verhaal vanuit aan werkende xml-config te sleuren en hier te pleuren, dan weet men hoe het er ongeveer uit moet zien.
[
Voor 83% gewijzigd door
Verwijderd op 02-04-2004 19:30
. Reden: Toevoegingen ]