mirror of
https://gitlab.com/shorewall/code.git
synced 2025-01-02 19:49:08 +01:00
Add /etc/shorewall/masq entry to PPTP server behind firewall with special external address
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@4587 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
This commit is contained in:
parent
1dd638513a
commit
fb33fd9aa1
@ -561,6 +561,18 @@ DNAT net loc:<emphasis><server address></emphasis> 47<
|
||||
# PORT(S) DEST
|
||||
DNAT net loc:<emphasis><server address></emphasis> tcp 1723 - <emphasis><external address></emphasis>
|
||||
DNAT net loc:<emphasis><server address></emphasis> 47 - - <emphasis><external address></emphasis></programlisting>
|
||||
|
||||
<para>You will also want to add this entry to your
|
||||
<filename>/etc/shorewall/masq</filename> file:</para>
|
||||
|
||||
<programlisting>#INTERFACE SUBNET ADDRESS PROTO
|
||||
<<emphasis>external interface</emphasis>> <<emphasis>server address</emphasis>> <<emphasis>external address</emphasis>> 47</programlisting>
|
||||
|
||||
<important>
|
||||
<para>Be sure that the above entry comes <emphasis
|
||||
role="bold">before</emphasis> any other entry that might match the
|
||||
server's address.</para>
|
||||
</important>
|
||||
</section>
|
||||
|
||||
<section id="ClientsBehind">
|
||||
@ -802,12 +814,13 @@ restart_pptp > /dev/null 2>&1 &</programlisting>
|
||||
<title>PPTP Client running on your Firewall with PPTP Server in an ADSL
|
||||
Modem</title>
|
||||
|
||||
<para>Some ADSL systems in Europe (most notably in Austria and the Netherlands) feature a PPTP
|
||||
server built into an ADSL <quote>Modem</quote>. In this setup, an ethernet
|
||||
interface is dedicated to supporting the PPTP tunnel between the firewall
|
||||
and the <quote>Modem</quote> while the actual internet access is through
|
||||
PPTP (interface ppp0). If you have this type of setup, you need to modify
|
||||
the sample configuration that you downloaded as described in this section.
|
||||
<para>Some ADSL systems in Europe (most notably in Austria and the
|
||||
Netherlands) feature a PPTP server built into an ADSL
|
||||
<quote>Modem</quote>. In this setup, an ethernet interface is dedicated to
|
||||
supporting the PPTP tunnel between the firewall and the
|
||||
<quote>Modem</quote> while the actual internet access is through PPTP
|
||||
(interface ppp0). If you have this type of setup, you need to modify the
|
||||
sample configuration that you downloaded as described in this section.
|
||||
<emphasis role="bold">These changes are in addition to those described in
|
||||
the <ulink url="shorewall_quickstart_guide.htm">QuickStart
|
||||
Guides</ulink>.</emphasis></para>
|
||||
|
Loading…
Reference in New Issue
Block a user