Tema: Re: Cisco vpn - iptables
Autorius: Igaliotinis patrulis!
Data: 2008-08-29 10:47:53
perejo ant hardwaro:)

"rabarbaras" <rabarbaras@zebra.lt> wrote in message 
news:g989e4$bdu$1@trimpas.omnitel.net...
>O kam state ?
>
> Igaliotinis patrulis! wrote:
>> Sveiki,
>>
>> Isorej stovi cisco vpn servas. Prisijungus ish musu vidinio tinklo 
>> naudojant cisco vpn klienta viskas veikia, pingai i remote vidinius ipus 
>> praeina. Prisijungiu su antru kompu i tuos pacius ipus - ping neatsako.. 
>> Galbut reikia itraukt kazka i mano servo iptables?
>>
>> Tokia pati problema anksciau buvo su windowsiniais vpnt connectionais - 
>> prisijungdavo tik vienas kompas ish lano. Parashiau cia ir kazkas patare 
>> uzkraut modprobe ip_nat_pptp, ir viskas susitvarke. Galbut kazko 
>> panashaus dar reikia ir cisco vpnui ? Cisco vpn kliento transportas - 
>> IPSec over UDP (NAT/PAT)..
>>
>> rc.nat atrodo taip:
>>
>> #!/bin/sh
>>
>> modprobe ip_tables
>> modprobe ip_conntrack
>> modprobe ip_conntrack_ftp
>> modprobe ip_conntrack_irc
>> modprobe iptable_nat
>> modprobe ip_nat_ftp
>> modprobe ip_nat_irc
>> modprobe ip_nat_pptp
>> modprobe ip_nat_proto_gre
>> modprobe ip_conntrack_proto_gre
>> modprobe ip_conntrack_pptp
>>
>> iptables -F INPUT
>> iptables -P INPUT ACCEPT
>> iptables -F OUTPUT
>> iptables -P OUTPUT ACCEPT
>> iptables -F FORWARD
>> iptables -P FORWARD DROP
>> iptables -t nat -F
>>
>> iptables -A FORWARD -i eth0 -o eth1 -m state --state 
>> ESTABLISHED,RELATED -j ACCEPT
>> iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
>> iptables -A FORWARD -j LOG
>> iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
>>
>> Jei neaiskiai aprashiau problema tai soriux :) bemiege naktis - sunkus 
>> rytas..
>>
>> Aciu 


3Dastronomyagricultureaudioautosautos.audiautos.audioautos.binariesautos.bmwautos.clubautos.fordautos.hondacrxautos.japanautos.mercedesautos.opelautos.sportautos.volvoautos.vwaviaavia.binariesbankcardsbinariesbooksbuildingcinemacommercecomp.hardwarecomp.softwarecomp.lietuvinimascomp.networksculturedarbas.ieskaudarbas.siulaudesigneconomicselectronicsfaunafauna.aquafauna.binariesfishingflorafotofoto.binariesgamesgames.csgames.onlinegsmgurmanaihumourhumour.binariesinternetlawmicrosoftmotomusicmusic.binariesmusic.instrumentsmusic.LT.binariesnavigacijaphppoliticsprogrammingrpgsportstudyingsveikatatalktesttranslationtransportationtraveltravel.binariestvunixvideovideo.binarieswatersportswwwwww.flashpdaautos.supermama.ltmobiledarbasretro.3Dretro.agricultureretro.astronomyretro.audioretro.autosretro.autos.audiretro.autos.audioretro.autos.binariesretro.autos.bmwretro.autos.clubretro.autos.fordretro.autos.hondacrxretro.autos.japanretro.autos.mercedesretro.autos.opelretro.autos.sportretro.autos.supermamaretro.autos.supermama.ltretro.autos.volvoretro.autos.vwretro.aviaretro.avia.binariesretro.bankcardsretro.beosretro.binariesretro.booksretro.buildingretro.cinemaretro.commerceretro.compretro.comp.hardwareretro.comp.lietuvinimasretro.comp.networksretro.comp.softwareretro.cultureretro.darbasretro.darbas.ieskauretro.darbas.siulauretro.designretro.economicsretro.electronicsretro.e-vejasretro.faunaretro.fauna.aquaretro.fauna.binariesretro.fishingretro.floraretro.fotoretro.foto.binariesretro.gamesretro.games.csretro.games.onlineretro.games.rpgretro.genealogijaretro.gsmretro.gurmanairetro.humourretro.humour.binariesretro.internetretro.YZFretro.YZF.nebukretro.YZF.nebuk.netikintisretro.YZF.nebuk.netikintis.bukretro.YZF.nebuk.netikintis.buk.tikintisretro.lawretro.microsoftretro.mobileretro.motoretro.musicretro.music.binariesretro.music.instrumentsretro.music.LTretro.music.LT.binariesretro.navigacijaretro.newsretro.news.taisyklesretro.newuserretro.pdaretro.phpretro.politicsretro.programmingretro.rpgretro.sportretro.studyingretro.sveikataretro.talkretro.translationretro.transportationretro.travelretro.travel.binariesretro.tvretro.unixretro.videoretro.video.binariesretro.watersportsretro.wwwretro.www.flashdiylt.rkm.news.announcelt.rkm.news.newuser