Hi,

since I never got a reply to my questions I sent, I'd like to follow
up on them myself.

I'm using a straightforward setup: internal LAN, gateway machine with
two interfaces, cable modem.  Outgoing connections work fine, as far as I 
can tell.

I did experience problems with ftp, specifically ftp:// URLs in netscape,
which confused me.  I had suspected that it had to do with the two ftp
modes, active and passive.  My question is this:  how does it work
in a stock 2.2.6 kernel?

a) Does an internal client have to be put in passive mode so that the
ftp module at the gw will work?

b) Or, can the ftp module handle active mode connections as well, in which
case the internal clients could be oblivious to the issue.

If the answer is a), then the follow up question would be: does anybody
know how to tell Netscape to use passive mode for ftp:// URLs.

I should point out that I think I've found a way to solve the problem: I
can simply use my ISP's http proxy, which apparently handles ftp:// URLs
as well.  However, I do not always want to use that proxy.


My second question had been regarding documentation and FAQs.  I realize
that IP masquerading is in flux, that there has been a transition from
older packages and modules to the newer 2.2.x/ipchains based approaches.
The FAQs and docs I've read are really confusing in that they never
state whether something applies to the former, the latter, or both.
Can anybody point me to what the applicable information for 2.2.x/ipchains
based kernel is?

Specifically, I am trying to get incoming connections to work.
Should I try the "ipmasqadm" command?
If I do, I get

>     [root@c80384-a rc.d]# ipmasqadm portfw -l
>     portfw: setsockopt failed: Invalid argument
>     Could not open "/proc/net/ip_masq/portfw"
>     Could not open "/proc/net/ip_portfw"
>     Check if you have enabled portforwarding
> 

What could be wrong?  Do I need to apply kernel patches or should
this work with a plain 2.2.6 kernel?

Thank you,

        - Godmar ([EMAIL PROTECTED])



_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to