No subject


Tue Nov 29 10:43:08 WST 2011


$OUTERIP = External IP
$INTTARGET = NT4 Server

.
    /sbin/modprobe ip_masq_portfw
.
/usr/sbin/ipmasqadm portfw -a -P tcp -L $OUTERIP 8000 -R $INTTARGET 8000
/sbin/ipchains --append input -p tcp -s 0/0 -d $OUTERIP 8000 -j ACCEPT
.
.


And from /usr/share/doc/ipmasqadm-0.4.2/redir-vs-portfw.txt

                REDIR2                       PORTFW
Place           user-space                   kernel

Method          connection "bouncing         reversed masq "spot"
                  at firewall"

Pros            . easy installation          . fast, low-resource
                . no kernel-side support       consumption
                  needed                     . load-balacing in LAST
                . load-balancing               patch-sets
                                             **internal servers SEE
conns
                                               from ACTUAL client **

Cons            . 1 process/connection       . kernel-patch needed for
2.0
                **internal servers SEE       . masquerader timeout
                  ALL connects from            handling may affect
                  firewall (NO WAY :)          total available connects
                  thus turning access        . usable, but still under
                  logs useless **              devel/test (THE Linux way
;)
                . process-handling:          . LOCAL (@firewall)
redirection
                  susceptible to scheduling    not available
                  issues
Resource        1 process/connection         1 masq entry/connection
usage                                          limited to max. masq
                                               entries

Regards,

Craig F.

> -----Original Message-----
> From: Brian Tombleson [mailto:brian at paradigmit.com.au] 
> Sent: Saturday, November 09, 2002 8:32 AM
> To: plug at plug.linux.org.au
> Subject: Re: [plug] redirection information required
> 
> 
> Jon Miller wrote:
> > On a site we have a NT4 server that is running an 
> application that uses
> > port 8000.  I need to know how can I redirect this through 
> a Linux rhl72
> > firewall. Just opening the port isn't working.
> > 
> > Thanks
> 
> Look at the 'redir' utility.
> 
> - Brian.
> 
> 
> 
> 
> 

------=_NextPart_000_0002_01C287CD.965280F0
Content-Type: application/x-pkcs7-signature;
	name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
	filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExDjAMBggqhkiG9w0CBQUAMIAGCSqGSIb3DQEHAQAAoIIJDDCC
ApswggIEoAMCAQICAwaV9TANBgkqhkiG9w0BAQQFADCBkjELMAkGA1UEBhMCWkExFTATBgNVBAgT
DFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3duMQ8wDQYDVQQKEwZUaGF3dGUxHTAbBgNV
BAsTFENlcnRpZmljYXRlIFNlcnZpY2VzMSgwJgYDVQQDEx9QZXJzb25hbCBGcmVlbWFpbCBSU0Eg
MjAwMC44LjMwMB4XDTAyMDEyMzIzMzgwNVoXDTAzMDEyMzIzMzgwNVowXjEPMA0GA1UEBBMGRm9z
dGVyMQ4wDAYDVQQqEwVDcmFpZzEVMBMGA1UEAxMMQ3JhaWcgRm9zdGVyMSQwIgYJKoZIhvcNAQkB
FhVmb3N0d2FyZUBpaW5ldC5uZXQuYXUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKb0orHe
ww/yaWmdFfjDBm5AUG4nzpbnn0UKgd7vjFQ4VtFkUZL4MzKpgx/35X7YFCUnSJAx96+JAs6+krHW
I5gV3qBZIQMO5ppvnUa5t/Xn3hgcYl+4/j/C5JWyslKJscUa5C3Iaqhoe/P2unqHHzTKlpK4S3uS
P7watPiZpXvXAgMBAAGjMjAwMCAGA1UdEQQZMBeBFWZvc3R3YXJlQGlpbmV0Lm5ldC5hdTAMBgNV
HRMBAf8EAjAAMA0GCSqGSIb3DQEBBAUAA4GBAB+xjmmMgJam8+mHYAXP0EY86nZY3r7Xa2iD0bkL
Fa8I60HYu2TV+DmXtSdUZtiv+BY45BqCtJa6xv0jzgBhMaBVgmvPczMe3L6oikmgwjm8Sr9Linry
K6A+twnpNdfMT4rdmb5adtjAoPXkGzrMWLSv7qMZIFgE9zgR3Uc6bWBlMIIDLTCCApagAwIBAgIB
ADANBgkqhkiG9w0BAQQFADCB0TELMAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTES
MBAGA1UEBxMJQ2FwZSBUb3duMRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMf
Q2VydGlmaWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFs
IEZyZWVtYWlsIENBMSswKQYJKoZIhvcNAQkBFhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29t
MB4XDTk2MDEwMTAwMDAwMFoXDTIwMTIzMTIzNTk1OVowgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQI
EwxXZXN0ZXJuIENhcGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1
bHRpbmcxKDAmBgNVBAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMT
G1RoYXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJl
ZW1haWxAdGhhd3RlLmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA1GnX1LCUZFtx6UfY
DFG26nKRsIRefS0Nj3sS34UldSh0OkIsYyeflXtL734Zhx2G6qPduc6WZBrCFG5ErHzmj+hND3Ef
QDimAKOHePb5lIZererAXnbr2RSjXW56fAylS1V/Bhkpf56aJtVquzgkCGqYx7Hao5iR/Xnb5VrE
HLkCAwEAAaMTMBEwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQDH7JJ+Tvj1lqVn
Yiqk8E0RYNBvjWBYYawmu1I1XAjPMPuoSpaKH2JCI4wXD/S6ZJwXrEcp352YXtJsYHFcoqzceePn
bgBHH7UNKOgCneSa/RP0ptl8sfjcXyMmCZGAc9AUG95DqYMl8uacLxXK/qarigd1iwzdUYRr5PjR
zneigTCCAzgwggKhoAMCAQICEGZFcrfMdPXPY3ZFhNAukQEwDQYJKoZIhvcNAQEEBQAwgdExCzAJ
BgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENhcGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgG
A1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNVBAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMg
RGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3
DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3RlLmNvbTAeFw0wMDA4MzAwMDAwMDBaFw0wNDA4
MjcyMzU5NTlaMIGSMQswCQYDVQQGEwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRIwEAYDVQQH
EwlDYXBlIFRvd24xDzANBgNVBAoTBlRoYXd0ZTEdMBsGA1UECxMUQ2VydGlmaWNhdGUgU2Vydmlj
ZXMxKDAmBgNVBAMTH1BlcnNvbmFsIEZyZWVtYWlsIFJTQSAyMDAwLjguMzAwgZ8wDQYJKoZIhvcN
AQEBBQADgY0AMIGJAoGBAN4zMqZjxwklRT7SbngnZ4HF2ogZgpcO40QpimM1Km1wPPrcrvfudG8w
vDOQf/k0caCjbZjxw0+iZdsN+kvx1t1hpfmFzVWaNRqdknWoJ67Ycvm6AvbXsJHeHOmr4BgDqHxD
QlBRh4M88Dm0m1SKE4f/s5udSWYALQmJ7JRr6aFpAgMBAAGjTjBMMCkGA1UdEQQiMCCkHjAcMRow
GAYDVQQDExFQcml2YXRlTGFiZWwxLTI5NzASBgNVHRMBAf8ECDAGAQH/AgEAMAsGA1UdDwQEAwIB
BjANBgkqhkiG9w0BAQQFAAOBgQAxsUtHXfkBceX1U2xdedY9mMAmE2KBIqcS+CKV6BtJtyd7BDm6
/ObyJOuR+r3sDSo491BVqGz3Da1MG7wD9LXrokefbKIMWI0xQgkRbLAaadErErJAXWr5edDqLiXd
iuT82w0fnQLzWtvKPPZE6iZph39Ins6ln+eE2MliYq0FxjGCA1kwggNVAgEBMIGaMIGSMQswCQYD
VQQGEwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRIwEAYDVQQHEwlDYXBlIFRvd24xDzANBgNV
BAoTBlRoYXd0ZTEdMBsGA1UECxMUQ2VydGlmaWNhdGUgU2VydmljZXMxKDAmBgNVBAMTH1BlcnNv
bmFsIEZyZWVtYWlsIFJTQSAyMDAwLjguMzACAwaV9TAMBggqhkiG9w0CBQUAoIICETAYBgkqhkiG
9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0wMjExMDkwMDU0MTdaMB8GCSqGSIb3
DQEJBDESBBDm1IXkFiAAUKa/9IdDKw7ZMFgGCSqGSIb3DQEJDzFLMEkwCgYIKoZIhvcNAwcwDgYI
KoZIhvcNAwICAgCAMAcGBSsOAwIHMA0GCCqGSIb3DQMCAgEoMAoGCCqGSIb3DQIFMAcGBSsOAwIa
MIGrBgkrBgEEAYI3EAQxgZ0wgZowgZIxCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENh
cGUxEjAQBgNVBAcTCUNhcGUgVG93bjEPMA0GA1UEChMGVGhhd3RlMR0wGwYDVQQLExRDZXJ0aWZp
Y2F0ZSBTZXJ2aWNlczEoMCYGA1UEAxMfUGVyc29uYWwgRnJlZW1haWwgUlNBIDIwMDAuOC4zMAID
BpX1MIGtBgsqhkiG9w0BCRACCzGBnaCBmjCBkjELMAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rl
cm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3duMQ8wDQYDVQQKEwZUaGF3dGUxHTAbBgNVBAsTFENl
cnRpZmljYXRlIFNlcnZpY2VzMSgwJgYDVQQDEx9QZXJzb25hbCBGcmVlbWFpbCBSU0EgMjAwMC44
LjMwAgMGlfUwDQYJKoZIhvcNAQEBBQAEgYCVVdqON/K+hC7ONn2qIkke1YAhOzirPUfgj9J6W/S0
Dr0DNnIcY+dAdI07JWyHfPDCH1BSsspm5BlMu6Jvvcs9xFLI6hRp46zZW2gKHDJfj2ccaj3amlFt
OwfRMpVwQmlK3DUk/BnAAuDJVjHSjn79R7hI/LlbGp6vRNgVAzdlQQAAAAAAAA==

------=_NextPart_000_0002_01C287CD.965280F0--



More information about the plug mailing list