John Lavin on 25 Jan 2004 22:19:02 -0000


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] New thinkpad with sarge


I'm not sure if switching would have helped, but I figured out a
resolution for my laptop.

It was indeed related to having a NAT'ed firewall already.  The default
behavior for these tools is to assume that 192.168.0.0/16 is reserved
for local use only.  Makes sense but since I'm firewalling between my
laptop and the local network (192.168.0.0/16), I want to allow those
local ips out.

I can comment out in gShield's configuration file: reserved_addresses
the entry 192.168.0.0/16 and this will allow my requests through...

Don't know if this is the best way, but it works...

Thanks,
-john

Will Dyson said:
> On Sun, 2004-01-25 at 11:01, John Lavin wrote:
> > Yes I am - my main box is nat'ed firewall connected directly to my dsl
> > modem.
> > 
> > I can run iptables commands before or after the gShield configuration
> > runs and it sounds like I need to un-block after the config runs, right?
> 
> I'm not familiar with gShield. Might there be a variable/switch you can
> set to indicate that you don't want those IPs blocked?
> 
> If not, I would seriously consider using a different firewall script.
> I've been using fiaif (there is a debian package, also
> http://www.fiaif.net/) for a while now.

Attachment: pgpaRPkiOqUuH.pgp
Description: PGP signature