[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Can't access aliased ip address



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wednesday 02 January 2002 07:02 pm, Jason M. Harvey wrote:
> yes, ipmasqadm should work for the port forwarding. actually, i know
> someone else who uses ipmasqadm to forward telnet traffic from his
> external ip to another pc with a private ip.
> having other users who may/will want pcanywhere may definitly be an
> issue for you to consider! i've never used it myself... one of these
> years i have to install it just to see what options it has - like
> specifying other ports! (yes, i'm stuck with that other os at my job!)

I know this isn't much to add, but it is an idea to look at if other users
might want pcanywhere access.

(Mind you, I'm not very experienced with advanced routing configurations, but
I'm fairly certain this is possible.)

Find out the IP address of the user with DSL who wants in to his system.
Then write a rule specifying that a request for the pcanywhere port on the
firewall from this (and only this) IP should go to _his_ internal machine.
Add more rules like this for other users.

I would say that is more secure than having multiple ports open for
pcanywhere, and much easier for your clients, as they wouldn't have to
reconfigure.

(Mind you, each person would require another line in your firewall script,
and no dynamic IP's)
<snip>
- --
vmann
reduce(lambda x,y:x+y,map(lambda
 x:chr(ord(x)^42),tuple('zS^BED\nX_FOY\x0b'))) GnuPG/PGP Fingerprint CE80
 018B D825 6DF1 4990  C15F E11A B17E 4A0C D133 Sair Linux and GNU Certified
 Administrator #563619
Whidbey Linux Users Group - http://www.wlug.net
http://vmann.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8NNEf4RqxfkoM0TMRAmcMAJ9aMJ8lMf4zq1sn8NoScsX0EG/m6gCggSiH
cpdAjKQ2/I0HVvWib1JG5xE=
=JGWK
-----END PGP SIGNATURE-----



Reply to: