Hello,

I have masq'ing and packet filtering established on my home network (firewall
machine has
two NICs, one is the external ADL connection, the other is 192.168.1.1 for the
internal network. I have an NT4.0 box (192.168.1.2) that I use. I can ping from
the NT box to the masq box, external sites, etc. HTTP is fine, as are most
other services (telnet, ftp, etc.). I assumed all was well with the world until
I noticed the following anomaly.

I use FTP Explorer for NT as my ftp client. I connected to Sunsite and as part
of the login messages noticed the following:

  ...230 Guest login ok, access restrictions apply
 SYST
....
PORT 192,168,1,2,4,15 (I may be wrong about the last two digits, I'm at work
and not at my machine at home)
200 PORT command successful
LIST
...
I can download successfully and everything appears to work ok, but I'm
concerned that my
internal net address is being passed to the external Internet. 

I use the ip_masq_ftp module per the masq instructions and it appears to load
ok. My 
questions are: Am I right to be concerned? Is my internal address really being
passed and if so,
how can I begin to determine what might be wrong with my firewall script? (I'm
using a strong firewall script and would be happy to send a copy if anyone is
interested.)
If my internal net address is being passed, I'm surprised that no Net services
or sites seem to 
choke on it, since as I said earlier, I have no problems with using the NT
machine on the Net.
My Linux is Redhat 5.2, IPFWADM for the packet filtering.

Thanks for your help.


Bob


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to