[ previous ] [ next ] [ threads ]
 
 From:  "a.gatta" <a dot gatta at tiscali dot it>
 To:  Peter Allgeyer <allgeyer at web dot de>, m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] Openvpn, problem with Inbound Nat on Opt interface
 Date:  Fri, 24 Mar 2006 23:04:19 +0100
Peter Allgeyer wrote:

>Am Freitag, den 24.03.2006, 16:40 +0100 schrieb a.gatta:
>
>  
>
>>Anyway, the redirect "rdr tun1 0.0.0.0/0 port 3389 -> 192.168.30.3 port 
>>3389 tcp" does not work but I just dont know why.
>>    
>>
>
>There is no firewall rule for incoming traffic to 192.168.30.3 port 3389 tcp!
>Go to Firewall->Rules->OPT1 in WebGUI and add an incoming rule on OPT1
>for tcp from any (or the remote lan) to 192.168.30.3 port 3389. Let me
>know, if that helps.
>
>BR,
>  PIT
>
>
>---------------------------------------------------------------------------
> copyleft(c) by |           I'm not sure whether that's actually
> Peter Allgeyer |   _-_     useful...   -- Larry Wall in
>                | 0(o_o)0   <199710011704 dot KAA21395 at wall dot org>
>---------------oOO--(_)--OOo-----------------------------------------------
>
>
>
>  
>
Hi Pit,
I applied the rule things are still the same.

Consider that yesterday I submited to the mailing list the config file 
when I was disperate, but I've already applied many many rules before.

In attach you will find the monoinfo from "status.php" and the 
configuration (xml) with the applied rule (any any pass).

Hope the helps.

Cheers
Interfaces

sis0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	options=40<POLLING>
	inet 23.250.58.114 netmask 0xfffff800 broadcast 23.250.63.255
	ether 00:0d:b9:01:12:0c
	media: Ethernet autoselect (10baseT/UTP)
	status: active
sis1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	options=40<POLLING>
	inet 192.168.30.2 netmask 0xffffff00 broadcast 192.168.30.255
	ether 00:0d:b9:01:12:0d
	media: Ethernet autoselect (100baseTX <full-duplex>)
	status: active
sis2: flags=8802<BROADCAST,SIMPLEX,MULTICAST> mtu 1500
	options=40<POLLING>
	ether 00:0d:b9:01:12:0e
	media: Ethernet autoselect (none)
	status: no carrier
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
	inet 127.0.0.1 netmask 0xff000000
tun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
	inet 10.20.0.6 --> 10.20.0.5 netmask 0xffffffff
	Opened by PID 80

Routing tables

Routing tables

Internet:
Destination        Gateway            Flags    Refs      Use  Netif Expire
default            23.250.56.1        UGSc        4    59910   sis0
10.20.0.1/32       10.20.0.5          UGSc        0        0   tun1
10.20.0.5          10.20.0.6          UH          8        0   tun1
23.250.56/21       link#1             UC          3        0   sis0
23.250.56.1        00:0c:86:8f:60:70  UHLW        4        0   sis0   1104
23.250.56.106      00:0c:86:8f:60:70  UHLW        0        1   sis0   1149
23.250.58.112      00:03:6f:03:f0:78  UHLW        1       28   sis0   1151
23.250.58.114      127.0.0.1          UGHS        0        0    lo0
127.0.0.1          127.0.0.1          UH          2       28    lo0
172.16.1/24        10.20.0.5          UGSc        0        0   tun1
192.168.0          10.20.0.5          UGSc        0        0   tun1
192.168.10         10.20.0.5          UGSc        0        0   tun1
192.168.30         link#2             UC          4        0   sis1
192.168.30.3       00:50:ba:6b:40:fc  UHLW        0    29076   sis1    994
192.168.30.10      00:0e:a6:7f:1d:8b  UHLW       13       81   sis1   1184
192.168.30.11      00:14:51:80:d0:c8  UHLW        0      369   sis1   1047
192.168.30.12      00:40:63:da:21:05  UHLW        0       13   sis1   1120
192.168.44         10.20.0.5          UGSc        0       79   tun1
192.168.45         10.20.0.5          UGSc        0        0   tun1
192.168.116        10.20.0.5          UGSc        0        0   tun1
192.168.250        10.20.0.5          UGSc        0        0   tun1

ipfw show

50000    382    230980 allow ip from 192.168.30.2 to any
50001    303     28182 allow ip from any to 192.168.30.2
65535 261980 161034597 allow ip from any to any

List of active MAP/Redirect filters:
map sis0 192.168.30.0/24 -> 0.0.0.0/32 proxy port ftp ftp/tcp
map sis0 192.168.30.0/24 -> 0.0.0.0/32 portmap tcp/udp auto
map sis0 192.168.30.0/24 -> 0.0.0.0/32
map tun1 192.168.30.0/24 -> 0.0.0.0/32 proxy port ftp ftp/tcp
map tun1 192.168.30.0/24 -> 0.0.0.0/32 portmap tcp/udp auto
map tun1 192.168.30.0/24 -> 0.0.0.0/32
rdr tun1 0.0.0.0/0 port 3389 -> 192.168.30.3 port 3389 tcp
rdr sis0 0.0.0.0/0 port 4662- 4672 -> 192.168.30.3 port 4662 tcp/udp
config-m0n0wall[1].local-20060324225636.xml (8.2 KB, text/xml)