From: <Use...@zo...> - 2008-04-06 18:08:07
|
dis...@bo...(Mike) 06.04.08 13:30 Once upon a time "Mike " shaped the electrons to say... http://www.securitypronews.com/it/networksystems/spn-21-20030731Windows2000ICSNATandIAS.html The machine on which ICS is configured is actually acting as a Network Address Translation (NAT) server. In a nutshell, Network Address Translation is usually used to translate between two connected ranges of IP addresses, usually one that is using a public IP address, and the other which is using a private address range. The `external' interface has a real IP address, and the internal interface is given the private address *192.168.0.1*. The system also acts as a sort of mini DHCP server, handing out IP addresses in the 192.168.0.0/24 range to clients on the internal network. To that end, clients use the addresses received, pointing to the 192.168.0.1 interface as their default gateway. The ICS system also does a DNS proxy function, meaning that all client hostname resolution requests will be forwarded to the ICS system for resolution via the configured external DNS parameters. So i assume: NAT does not work, the pakets from 192.168.100.2 are simply forwarded to the default gateway, which hapens to be your DNS server. Let DHCP determine the IP of the guest or choose 192.168.0.x instead of endless guessing: Install wireshark and see which IPs are used where. > +-----------------------+ +------------------------+ > | coLinux (guest) | | WinXP (host) | > | | | wtap0: (Win-TAP32)<-+ | > | eth0: | | IP:192.168.100.1 | | > | IP 192.168.100.2 <--|------|--> | | > | gateway: 192.168.100.1| | ICS | > +-----------------------+ +---|--> | | > | | PhysicalNetwork: <-+ | > | | IP:192.168.2.10 (wifi) | > | | gateway: 192.168.2.254 | > | +------------------------+ > | +------------------------+ > | | lan router (netgear) | > | | 192.168.2.254 | > +---|--> | > | | > +---|--> | > | | IP: 192.168.1.253 | > | | gateway: 192.168.1.254 | > | +------------------------+ > | > | +------------------------+ > | | ADSL router (speedtouch| +----------------+ > | | IP:192.168.1.254 | | | > +---|--> <---|--|other lan router| > | | |IP:192.168.1.252| > +------------------------+ +--|--> | +----------------+ > | Provider | | | Dynamic IP (DHCP): | > | <--|--+ | | > | | | | > +------------------------+ +------------------------+ > ============================================================= >>>Destination Gateway Genmask Flags Metric Ref Use >>>Iface 192.168.100.0 * 255.255.255.0 U 0 0 >>>0 eth0 default 192.168.100.1 0.0.0.0 UG 0 >>>0 0 eth0 >> >> /etc/resolv.conf? >nameserver 192.168.2.254 Rainer---<=====> Vertraulich // Key-ID:38F34C59 // <=====>--------------ocholl, Kiel, Germany ------------ |