[Firewall] nat forwarding problem

Arno van Amersfoort arnova at rocky.eld.leidenuniv.nl
Tue Jul 8 07:21:08 MDT 2008


Yep, it's a bug, it should have been IFS=' ,' . Thanks for reporting it, 
I've fixed it for the upcoming 1.9.0-rc1 release....

A.

Dan wrote:
> Hello,
> 
> I use the last arno-iptables-firewall (1.9.0-beta3)
> I have some strange errors messages if I use two external interface
> Enabling SNAT via external interface(s): eth1 eth2
> Adding (internal) host(s): 192.168.1.0/24 <http://192.168.1.0/24>
> (eth1 eth2) Forwarding(NAT) TCP port(s) 0/0:3389 to 192.168.1.254 
> <http://192.168.1.254>
> Warning: wierd character in interface `eth1 eth2' (No aliases, :, ! or *).
> Warning: wierd character in interface `eth1 eth2' (No aliases, :, ! or *).
> Warning: wierd character in interface `eth1 eth2' (No aliases, :, ! or *).
> No NAT forwarding works of course ... 
> 
> I look in the code, and I found in the NAT port forwarding part the code :
> *IFS=','
> *    for shost in `ip_range "$shosts"`; do
>       for sport in $sports; do
>         for destip in $destips; do
>           # Portforward for all specified interfaces
>           for eif in $interfaces; do
>  
> As you see the IFS variable is define as ',' but the $interface variable 
> it's a space separated variable.
> I am not sure that's a bug but only a suggestion to look for ...
>  
> Thanks in advance
> Daniel Paten
> 
> 
> ------------------------------------------------------------------------
> 
> _______________________________________________
> Firewall mailing list
> Firewall at lists.btito.net
> http://lists.btito.net/mailman/listinfo/firewall_lists.btito.net
> Arno's (Linux IPTABLES Firewall) Homepage:
> http://rocky.eld.leidenuniv.nl

-- 
Arno van Amersfoort
E-mail    : arnova at rocky.eld.leidenuniv.nl
Donations are welcome through Paypal!
---------------------------------------------------------------------------
Arno's (Linux IPTABLES Firewall) Homepage:
http://rocky.eld.leidenuniv.nl



More information about the Firewall mailing list