|
From: <no...@so...> - 2002-06-01 22:37:32
|
Feature Requests item #563416, was opened at 2002-06-01 17:37 You can respond by visiting: http://sourceforge.net/tracker/?func=detail&atid=410646&aid=563416&group_id=34096 Category: Configuration / Scripts Group: v0.6 Status: Open Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: Static routes / arp entries Initial Comment: check what we can use here, files are attached. ---------------------------------------------- From: "Matthew J. Axsom" <MA...@Te...> To: <he...@de...> Reply-To: <MA...@Te...> Subject: Contribution - Static routes / arp entries Date: Thu, 16 May 2002 12:55:43 -0700 X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2911.0) Hi Heiko, After working with devil-linux for a week or so I found it arduous to keep manually entering static routes / arp entries for my DMZ interface. I checked the devil-linux cvs for any updates or solutions and didn't see any so here is a possible solution for your review. I do realize that many people may just add the route / proxy additions to the firewall.rules script however this is less than ideal if you want to use fwbuilder for your rules generation. Most installations static entries / proxy arps won't change while their firewall.rules will which made it more desirable to place these in another script. This is a really simple addition. I made it flexible enough that you can specify a begin and end address for say a whole class c block to listen on your external interface and proxy arp to the dmz interface. It requires two additional scripts and a modification to the config script to add the variable ADD_STATIC_ROUTES right before the firewall rules are loaded. Summary ----------- /etc/sysconfig/config - Addition of variable ADD_STATIC_ROUTES /etc/init.d/routes - New startup script /etc/routes.conf - New configuration script chown 700 /etc/init.d/routes chown 700 /etc/routes.conf Changes to runlevels ------------------------- ln -s ../routes /etc/init.d/rc3.d/S06routes ln -s ../routes /etc/init.d/rc5.d/S06routes Attached find the three files in question Additional Info which may or may not be helpful ---------------------------------------------------------- Here is my basic setup to get a picture default gateway = 66.247.73.174 eth0 - external static "66.247.73.169" 255.255.255.248 eth1 - dmz bogus address "192.168.254.254" public range 170-173 are arped via eth0 and a route entry eth2 - internal "192.168.0.1" Using fwbuilder for iptables generation With this setup I only give up one static ip address for the firewall ext interface... many other references on the net show how to create dmz's but give up extra addresses because they use their public addresses for the dmz port. The dmz bogus address is just that bogus, it prevents the routing table from seeing it as 0.0.0.0 and screwing things up for your internal interface. Most isp's don't assign blocks large enough these days to be worth subnetting out so I find this works well and preserves the address space for those of us with small subnets. Thanks, Matt Axsom ---------------------------------------------------------------------- You can respond by visiting: http://sourceforge.net/tracker/?func=detail&atid=410646&aid=563416&group_id=34096 |
|
From: SourceForge.net <no...@so...> - 2003-04-11 03:13:24
|
Feature Requests item #563416, was opened at 2002-06-01 17:37 Message generated for change (Settings changed) made by smiley73 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=563416&group_id=34096 Category: Configuration / Scripts Group: v0.6 >Status: Deleted Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: Static routes / arp entries Initial Comment: check what we can use here, files are attached. ---------------------------------------------- From: "Matthew J. Axsom" <MA...@Te...> To: <he...@de...> Reply-To: <MA...@Te...> Subject: Contribution - Static routes / arp entries Date: Thu, 16 May 2002 12:55:43 -0700 X-Mailer: Microsoft Outlook CWS, Build 9.0.2416 (9.0.2911.0) Hi Heiko, After working with devil-linux for a week or so I found it arduous to keep manually entering static routes / arp entries for my DMZ interface. I checked the devil-linux cvs for any updates or solutions and didn't see any so here is a possible solution for your review. I do realize that many people may just add the route / proxy additions to the firewall.rules script however this is less than ideal if you want to use fwbuilder for your rules generation. Most installations static entries / proxy arps won't change while their firewall.rules will which made it more desirable to place these in another script. This is a really simple addition. I made it flexible enough that you can specify a begin and end address for say a whole class c block to listen on your external interface and proxy arp to the dmz interface. It requires two additional scripts and a modification to the config script to add the variable ADD_STATIC_ROUTES right before the firewall rules are loaded. Summary ----------- /etc/sysconfig/config - Addition of variable ADD_STATIC_ROUTES /etc/init.d/routes - New startup script /etc/routes.conf - New configuration script chown 700 /etc/init.d/routes chown 700 /etc/routes.conf Changes to runlevels ------------------------- ln -s ../routes /etc/init.d/rc3.d/S06routes ln -s ../routes /etc/init.d/rc5.d/S06routes Attached find the three files in question Additional Info which may or may not be helpful ---------------------------------------------------------- Here is my basic setup to get a picture default gateway = 66.247.73.174 eth0 - external static "66.247.73.169" 255.255.255.248 eth1 - dmz bogus address "192.168.254.254" public range 170-173 are arped via eth0 and a route entry eth2 - internal "192.168.0.1" Using fwbuilder for iptables generation With this setup I only give up one static ip address for the firewall ext interface... many other references on the net show how to create dmz's but give up extra addresses because they use their public addresses for the dmz port. The dmz bogus address is just that bogus, it prevents the routing table from seeing it as 0.0.0.0 and screwing things up for your internal interface. Most isp's don't assign blocks large enough these days to be worth subnetting out so I find this works well and preserves the address space for those of us with small subnets. Thanks, Matt Axsom ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=563416&group_id=34096 |