Differences between revisions 2 and 3
Revision 2 as of 2004-10-01 00:50:41
Size: 20431
Editor: 61
Comment:
Revision 3 as of 2004-10-01 07:07:01
Size: 5559
Editor: TomHiggins
Comment: DeSpam, Now in Smokey Flavor
Deletions are marked like this. Additions are marked like this.
Line 123: Line 123:
[http://www.shop263.com/i8/1.htm »îÐÔÌ¿]
[http://www.shop263.com/i8/2.htm ³¤Ò¶Ï©]
[http://www.shop263.com/i8/3.htm ´×ËáÒìÁúÄÔõ¥]
[http://www.shop263.com/i8/4.htm µ¥ÄþËá]
[http://www.shop263.com/i8/5.htm ¶¡»ùÄÆ»ÆÒ©]
[http://www.shop263.com/i8/6.htm ¶ÔÃÏÍé]
[http://www.shop263.com/i8/7.htm ¶þÇâËÉÓÍ´¼]
[http://www.shop263.com/i8/8.htm ¶þÇâÒÒËáËÉÓÍõ¥]
[http://www.shop263.com/i8/9.htm ¶þÑõ»¯Áòëå]
[http://www.shop263.com/i8/10.htm ·¢ÅݼÁ]
[http://www.shop263.com/i8/11.htm ¸¯Ö²Ëá]
[http://www.shop263.com/i8/12.htm ËÉÏãÊ©½º¼Á]
[http://www.shop263.com/i8/13.htm ¹¤Òµ¼¶ÂÈÒÒËá]
[http://www.shop263.com/i8/14.htm ËÉÏãÊ÷Ö¬]
[http://www.shop263.com/i8/15.htm ¹Ì»¯¼Á]
[http://www.shop263.com/i8/16.htm ÝÆÏ©Ê÷Ö¬]
[http://www.shop263.com/i8/17.htm ËÉÏã¸ÄÐÔÊ÷Ö¬]
[http://www.shop263.com/i8/18.htm ľÖÊÈܼÁÌ¿]
[http://www.shop263.com/i8/19.htm ËÉÏãëæ]
[http://www.shop263.com/i8/20.htm ËÉÏãõ¥]
[http://www.shop263.com/i8/21.htm ËÉÓÍ]
[http://www.shop263.com/i8/22.htm ËÉÓÍ´¼]
[http://www.shop263.com/i8/23.htm ËÉÓ;«]
[http://www.shop263.com/i8/24.htm Ì¿»¯ÁÏ]
[http://www.shop263.com/i8/25.htm »îÐÔÌ¿]
[http://www.shop263.com/i8/26.htm ÝÆÏ©±½ÒÒÏ©Ê÷Ö¬]
[http://www.shop263.com/i8/27.htm ÝÆÏ©·ÓÈ©Ê÷Ö¬]
[http://www.shop263.com/i8/28.htm ÝÆÏ©·ÓÊ÷Ö¬]
[http://www.shop263.com/i8/29.htm ÝÆÏ©Ê÷Ö¬]
[http://www.shop263.com/i8/30.htm ÎÞË®´×ËáÄÆ]
[http://www.shop263.com/i8/31.htm ·Û×´Ì¿]
[http://www.shop263.com/i8/32.htm Ï㾫ÏãÁÏ]
[http://www.shop263.com/i8/33.htm ËÉ´¼ÓÍ]
[http://www.shop263.com/i8/34.htm ÒÒ»ùÄÆ»ÆÒ©]
[http://www.shop263.com/i8/35.htm ÒÒËá¶þÇâËÉÓÍõ¥]
[http://www.shop263.com/i8/36.htm ËÉÏã°·]
[http://www.shop263.com/i8/37.htm ÒÒËáËÉÓÍõ¥]
[http://www.shop263.com/i8/38.htm Ò쳤Ҷϩ]
[http://www.shop263.com/i8/39.htm ÒìÁúÄÔ]
[http://www.shop263.com/i8/40.htm ÔöÕ³Ê÷Ö¬]
[http://www.shop263.com/i8/41.htm ÕÁÄÔ·Û]
[http://www.shop263.com/i8/42.htm Ö¬ËɽÚÓÍ]
[http://www.shop263.com/i8/43.htm Ö¬ËÉÏã]
[http://www.shop263.com/i8/44.htm ÉÕ¼î]
[http://www.shop263.com/i8/45.htm ûʳ×ÓËá]
[http://www.shop263.com/i8/46.htm Ë«ÝÆÏ©]
[http://www.shop263.com/i8/47.htm Ë«ÎìÏ©]
[http://www.shop263.com/i8/48.htm Ë«ÒÒËáÄÆ]
[http://www.shop263.com/i8/49.htm Ë®ºÏëÂ]
[http://www.shop263.com/i8/50.htm ˳ÝåÍé]
[http://www.shop263.com/i8/51.htm ËÄÇâ¿·´¼]
[http://www.shop263.com/i8/52.htm ËɽÚÓÍ]
[http://www.shop263.com/i8/53.htm ËÉÏã]
[http://www.shop263.com/i8/54.htm ¹ýÑõ»¯Çâ]
[http://www.shop263.com/i8/55.htm ºÏ³ÉÕÁÄÔ·Û]
[http://www.shop263.com/i8/56.htm Ì¿]
[http://www.shop263.com/i8/57.htm Ò¬¿ÇÌ¿]
[http://www.shop263.com/i8/58.htm »·ÑõÊ÷Ö¬]
[http://www.shop263.com/i8/59.htm »Ç»¯µ¥Äþ]
[http://www.shop263.com/i8/60.htm »Ç»¯èེ]
[http://www.shop263.com/i8/61.htm »îÐÔÌ¿]
[http://www.shop263.com/i8/62.htm ½ºÕ³¼Á]
[http://www.shop263.com/i8/63.htm ½á¾§´×ËáÄÆ]
[http://www.shop263.com/i8/64.htm ¾ÛºÏËÉÏã]
[http://www.shop263.com/i8/65.htm ¾ÛÂÈÒÒÏ©Ê÷Ö¬]
[http://www.shop263.com/i8/66.htm ݨϩ]
[http://www.shop263.com/i8/67.htm èེµ¥ÄþÀà]
[http://www.shop263.com/i8/68.htm Ï㾫]
[http://www.shop263.com/i8/69.htm ÂíÀ´ËÉÏã]
[http://www.shop263.com/i8/70.htm »îÐÔÌ¿]
[http://www.shop263.com/i-2/1.htm ±àÖ¯´ü]
[http://www.shop263.com/i-2/2.htm ½¹·Û]
[http://www.shop263.com/i-2/3.htm µç¼«]
[http://www.shop263.com/i-2/4.htm ¸ß̼ʯī]
[http://www.shop263.com/i-2/5.htm úÖÊ»îÐÔÌ¿]
[http://www.shop263.com/i-2/6.htm ÈܼÁ]
[http://www.shop263.com/i-2/7.htm ÍÑÁò]
[http://www.shop263.com/i-2/8.htm Îå¿ó]
[http://www.shop263.com/i-2/9.htm Òº»¯Ê¯ÓÍÆø]
[http://www.shop263.com/i-2/10.htm ÒûÁÏ]
[http://www.shop263.com/i-2/11.htm ½¹Ì¿]
[http://www.shop263.com/i-2/12.htm Ô²¿×°å]
[http://www.shop263.com/i-2/13.htm ÄòËØ]
[http://www.shop263.com/i-2/14.htm ÇáÖÊÓÍ]
[http://www.shop263.com/i-2/15.htm Ë®Äà]
[http://www.shop263.com/i-2/16.htm Ë®Äàש]
[http://www.shop263.com/i-2/17.htm Ì¼ËØÊ¯Ä«]
[http://www.shop263.com/i-2/18.htm ÌúºÏ½ð]
[http://www.shop263.com/i-2/19.htm ½¹»¯±½]
[http://www.shop263.com/i-2/20.htm ½¹Ì¿]
[http://www.shop263.com/i-2/21.htm ¿ÉÅòÕÍʯī]
[http://www.shop263.com/i-2/22.htm Áó·Ý]
[http://www.shop263.com/i-2/23.htm ú̼]
[http://www.shop263.com/i-2/24.htm ÖØ±½]
[http://www.shop263.com/i-3/1.htm þºÏ½ð]
[http://www.shop263.com/i-3/2.htm þÖÊÄÍ»ð]
[http://www.shop263.com/i-3/3.htm Ãñ±¬Æ÷²Ä]
[http://www.shop263.com/i-3/4.htm ·À±©Æ÷²Ä]
[http://www.shop263.com/i-3/5.htm ÃñÓñ¬ÆÆÆ÷²Ä]
[http://www.shop263.com/i-3/6.htm ħÊõµ¯ÑÌ»¨]
[http://www.shop263.com/i-3/7.htm Å軨]
[http://www.shop263.com/i-3/8.htm Æû³µÔËÊä]
[http://www.shop263.com/i-3/9.htm ±£ÎÂש]
[http://www.shop263.com/i-3/10.htm ÄÍ»ð²ÄÁÏ]
[http://www.shop263.com/i-3/11.htm È黯¼Á]
[http://www.shop263.com/i-3/12.htm È黯ըҩ]
[http://www.shop263.com/i-3/13.htm ¸ÖͰ]
[http://www.shop263.com/i-3/14.htm ÊÒÄÚÑÌ»¨]
[http://www.shop263.com/i-3/15.htm ˹ÅÌ]
[http://www.shop263.com/i-3/16.htm ËÜÁϵ¼±¬¹Ü]
[http://www.shop263.com/i-3/17.htm Íæ¾ßÑÌ»¨]
[http://www.shop263.com/i-3/18.htm лéÀñÅÚ]
[http://www.shop263.com/i-3/19.htm ÑÌ»¨]
[http://www.shop263.com/i-3/20.htm ÑÌ»¨±¬Öñ]
[http://www.shop263.com/i-3/21.htm À×¹Ü]
[http://www.shop263.com/i-3/22.htm ÑÒʯ·Û]
[http://www.shop263.com/i-3/23.htm Ë®½ºÕ¨Ò©]
[http://www.shop263.com/i-3/24.htm Ñæ»ð]
[http://www.shop263.com/i-3/25.htm ÒÒ´¼°·]
[http://www.shop263.com/i-3/26.htm Õ³ÍÁש]
[http://www.shop263.com/i-3/27.htm ÖØï§ÓÍÕ¨Ò©]
[http://www.shop263.com/i-3/28.htm ÖýÔìß»]
[http://www.shop263.com/i-3/29.htm µ¼»ðË÷]
[http://www.shop263.com/i-3/30.htm ÌÕ´ÉҤ¯]
[http://www.shop263.com/i-3/31.htm Íæ¾ß]
[http://www.shop263.com/i-3/32.htm ÂÞÂíÖò¹â]
[http://www.shop263.com/i-3/33.htm ï§ÌÝÕ¨Ò©]
[http://www.shop263.com/i-3/34.htm °×Ì¿ºÚ]
[http://www.shop263.com/i-3/35.htm ±ö¹Ý²ÍÒû]
[http://www.shop263.com/i-3/36.htm ²Ê»¨]
[http://www.shop263.com/i-3/37.htm ³éÉ´ÊÎÆ·]
[http://www.shop263.com/i-3/38.htm µ¼±¬¹Ü]
[http://www.shop263.com/i-3/39.htm »¨Í²]
[http://www.shop263.com/i-3/40.htm ˖Ȭ]
[http://www.shop263.com/i-3/41.htm µçÀ×¹Ü]
[http://www.shop263.com/i-3/42.htm ¶à¿×Á£×´ï§ÓÍÕ¨Ò©]
[http://www.shop263.com/i-3/43.htm ¹Ü¿Ç]
[http://www.shop263.com/i-3/44.htm ·¯ÍÁ]
[http://www.shop263.com/i-3/45.htm ÂÁþº¬½ð·Û]
[http://www.shop263.com/i-3/46.htm Ñô¼«]
[http://www.shop263.com/i-3/47.htm ÄÍ»ð²ÄÁÏ]
[http://www.shop263.com/i-3/48.htm ¸ßÂÁש]
[http://www.shop263.com/i-3/49.htm ú¿ó]
[http://www.shop263.com/i-3/50.htm ÑÌÉ¡]
[http://www.shop263.com/i-3/51.htm ¹¤³Ì±¬ÆÆ]
[http://www.shop263.com/i-3/52.htm ½¨Öþ]
[http://www.shop263.com/i-3/53.htm »ðÀ×¹Ü]
[http://www.shop263.com/i-3/54.htm Ë®¿Úש]
[http://www.shop263.com/i-3/55.htm »ìºÏÑÌ»¨]
[http://www.shop263.com/i-3/56.htm »ð¹¤]
[http://www.shop263.com/i-3/57.htm »ð¼ý]
[http://www.shop263.com/i-3/58.htm »ðÀ×¹Ü]
[http://www.shop263.com/i-3/59.htm ÄÍ»ðש]
[http://www.shop263.com/i-3/60.htm À×¹Ü]
[http://www.shop263.com/i-3/61.htm Àä¹âÅçȪ]
[http://www.shop263.com/i-3/62.htm Àñ»¨µ¯]
[http://www.shop263.com/i-3/63.htm ä¯Ñô»¨ÅÚ]
[http://www.shop263.com/i-412/1.htm ¹¤ÒÕÆ·]
[http://www.shop263.com/i-412/2.htm ·¼ÏãÖÆÆ·]
[http://www.shop263.com/i-412/3.htm ãåÔ¡]
[http://www.shop263.com/i-412/4.htm È«·ú±íÃæ»îÐÔ¼Á]
[http://www.shop263.com/i-412/5.htm º¬·ú±íÃæ»îÐÔ¼Á]
[http://www.shop263.com/i-412/6.htm µç×Ó»¯Ñ§]
[http://www.shop263.com/i-412/7.htm ·ú±íÃæ»îÐÔ¼Á]
[http://www.shop263.com/i-412/8.htm ·ú̼±íÃæ»îÐÔ¼Á]










 

 

 

  

 

[http://www.haishun.net ÃŽû]
[http://www.asp169.com/crm.htm »¯×±Æ·]
[http://www.asp169.com/marketingsoft3.htm Õ½ÂÔ×Éѯ]
[http://www.asp169.com/marketingsoft4.htm ÎäÒÄɽ]
[http://www.asp169.com/marketingsoft5.htm Êý¾Ý»Ö¸´]
[http://www.asp169.com/marketingsoft5.htm Êý¾ÝÐÞ¸´]
[http://www.asp169.com/marketingsoft5.htm Ó²ÅÌÊý¾Ý»Ö¸´]
[http://www.asp169.com/marketingsoft5.htm Ó²ÅÌÊý¾ÝÐÞ¸´]
[http://www.haishun.net ¼à¿Ø]
[http://www.genset-sh.com ·¢µç»ú]
[http://www.haishun.net/p_mjds.htm ÃŽû]
[http://www.haishun.net/p_mjds_dmmj.htm ÃŽû]
[http://www.haishun.net/p_mjds_lwmj.htm ÃŽû]
[http://www.haishun.net/p_mjds_yjs.htm ÃŽû]
[http://www.haishun.net/cctv.htm ¼à¿Ø]
[http://www.haishun.net/p_cctv_jk.htm ¼à¿Ø]
[http://www.haishun.net/p_cctv_jk_sxj.htm ¼à¿Ø]
[http://www.haishun.net/p_cctv_jk_xsq.htm ¼à¿Ø]
[http://www.haishun.net/p_cctv_jk_yplxj.htm ¼à¿Ø]
[http://www.haishun.net/p_cctv_jk_yt.htm ¼à¿Ø]
[http://www.haishun.net/p_cctv_jk_zj.htm ¼à¿Ø]
[http://www.7766888.com ÐéÄâÖ÷»ú]
[http://haishun11.51.net ÐéÄâÖ÷»ú]
[http://www.7766888.com/introcom.htm aspÐéÄâÖ÷»ú]
[http://www.7766888.com/introcn.htm phpÐéÄâÖ÷»ú]
[http://www.7766888.com/u_puji.htm unixÐéÄâÖ÷»ú]
[http://www.7766888.com/mysql.htm windowsÐéÄâÖ÷»ú]
[http://www.7766888.com/u_jingji.htm ´¿¿Õ¼äÐéÄâÖ÷»ú]
[http://www.7766888.com/u_biaozhun.htm ÐéÄâÖ÷»ú]
[http://www.7766888.com/u_zhiqiang.htm ÐéÄâÖ÷»ú]
[http://www.7766888.com/w_jingji.htm ÐéÄâÖ÷»ú]
[http://www.7766888.com/w_biaozhun.htm ÐéÄâÖ÷»ú]
[http://www.asp169.com/marketingsoft1.htm ¿Õѹ»ú]
[http://www.asp169.com/marketingsoft2.htm ѹËõ»ú]
[http://www.asp169.com/zhaoguan.htm Ïû¶¾¼Á]
[http://www.xsjby.cn »¯¹¤±Ã]
[http://www.asp169.com/zhaoguan2.htm ¶þÑõ»¯ÂÈ]
[http://www.fm360.net ÍøÖ·´óÈ«]
[http://www.fm360.net/page/001.html ÍøÖ·´óÈ«]
[http://www.fm360.net/page/game.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/software.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/jinshi.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/music.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/053.html ÍøÖ·´óÈ«]
[http://www.fm360.net/page/flash.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/newsweek.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/club.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/stock.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/love.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/netcard.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/025.html ÍøÖ·´óÈ«]
[http://www.fm360.net/page/hardware.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/sport.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/shouji.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/ym.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/ylbj.htm ÍøÖ·´óÈ«]
[http://www.fm360.net/page/car.htm ÍøÖ·´óÈ«]
[http://www.jifamark.com ÏߺŻú]
[http://www.jifamark.com/xhj.htm ÏߺŻú]
[http://www.jifamark.com ´òºÅ»ú]
[http://global.garrywa.com/index1.htm gemstone globe]
[http://global.garrywa.com/recommend.asp gemstone globe]
[http://global.garrywa.com/productclass.asp gemstone globe]
[http://global.garrywa.com gemstone globe]
[http://global.garrywa.com/order.htm gemstone globe]
[http://fireworks.garrywa.com Fireworks]
[http://fireworks.garrywa.com/about.htm Fireworks]
[http://fireworks.garrywa.com/factory.htm Fireworks]
[http://fireworks.garrywa.com/index.htm Fireworks]
[http://fireworks.garrywa.com/pro.htm Fireworks]
[http://fireworks.garrywa.com/faq.htm Fireworks]
[http://fireworks.garrywa.com/safty.htm Fireworks]
[http://fireworks.garrywa.com/contact.htm Fireworks]
[http://fireworks.garrywa.com/productclass.asp Fireworks]
[http://www.funasia.cn ×°ÐÞ]
[http://www.funasia.cn ÍŹº]
[http://www.funasia.cn/pinpai.asp ×°ÐÞ]
[http://www.funasia.cn/client/gb_list.asp ×°ÐÞ]
[http://www.funasia.cn/design/index.asp ×°ÐÞ]
[http://www.funasia.cn/funasiaHome/index.asp ×°ÐÞ]
[http://www.funasia.cn/jiancai.asp ×°ÐÞ]
[http://www.funasia.cn/shishang.asp ×°ÐÞ]
[http://www.funasia.cn/mall/AboutOur.htm ÍŹº]
[http://www.sec66.com ѹËõ»ú]
[http://www.sec66.com ¿Õѹ»ú]
[http://www.sec66.com/ym001/pro.asp ¿Õѹ»ú]
[http://www.sec66.com/index001.htm ¿Õѹ»ú]
[http://www.sec66.com/ym001/intr.htm ¿Õѹ»ú]
[http://www.sec66.com/ym001/application.htm ѹËõ»ú]
[http://www.sec66.com/ym001/service.htm ѹËõ»ú]
[http://www.sec66.com/ym001/news.htm ѹËõ»ú]
[http://www.sec66.com/ym001/bbs.htm ѹËõ»ú]
[http://www.sec66.com/ym001/en_intr.htm ѹËõ»ú]
[http://www.genset-sh.com ·¢µç»ú]
[http://www.genset-sh.com/cai.asp ·¢µç»ú]
[http://www.genset-sh.com/tancu.asp ·¢µç»ú]
[http://www.genset-sh.com/xi3.asp ·¢µç»ú]
[http://www.genset-sh.com/lan.asp ·¢µç»ú]
[http://www.genset-sh.com/leng.asp ·¢µç»ú]
[http://www.genset-sh.com/jiyou.asp ·¢µç»ú]
[http://www.genset-sh.com/ranyou.asp ·¢µç»ú]
[http://www.genset-sh.com/kuongqi.asp ·¢µç»ú]
[http://www.genset-sh.com/ssss.asp ·¢µç»ú]
[http://www.zj-df.com ¼õËÙ»ú]
[http://www.xhhj.com.cn ÀëÐÄ»ú]
[http://www.cndevi.com »¯×±Æ·]
[http://www.cndevi.com/About.asp »¯×±Æ·]
[http://www.cndevi.com/Product.asp »¯×±Æ·]
[http://www.cndevi.com/sale.asp »¯×±Æ·]
[http://www.cndevi.com/Went.asp »¯×±Æ·]
[http://www.sinostrategy.com Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/index.asp Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/service/index.asp Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/expertise/index.asp Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/practice/index.asp Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/knowledge/index.asp Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/connect/index.asp Õ½ÂÔ×Éѯ]
[http://www.sinostrategy.com/finalbexcel/company/media_center/index.asp Õ½ÂÔ×Éѯ]
[http://www.hdfix.com.cn Êý¾Ý»Ö¸´]

Notes on nocat exception rules.

Here are notes of an attempt to adapt [http://lists.nocat.net/pipermail/nocat/2003-August/003543.html] for use at PTP Node375 and should eventually be generalized.

An earlier post is simpler and does not include the port forwarding. [http://lists.nocat.net/pipermail/nocat/2003-February/002816.html]

Two cases:

  • Allow a specific ip_number,mac_addr pair through firewall before nocat splash rules apply. (nocat exception)
  • Allow inbound traffic to specific ports of the external interface of the nocat box to forward into an internal machine. (port forwarding)

Currently this setup works in the first case but not the second. One thing that is different here is when the script is called. I simpilifed by putting it into initialize.fw and perhaps it should happen elsewhere as dmzs recommends.

Setup notes for Node375

A. Add the following line to the end of /usr/share/nocatauth/gateway/bin/initialize.fw

  • /usr/share/nocatauth/gateway/bin/intel.rules.sh

B. Add the following lines to /etc/dhcpd.conf

  • host cowcam {
     hardware ethernet 00:06:25:1A:5E:57;
     fixed-address 10.11.19.12;
     option host-name "cowcam";
    }
    
    host bbs {
     hardware ethernet 00:04:23:48:7E:98;
     fixed-address 10.11.19.99;
     option host-name "bbs";
    }

C. Create new file /usr/share/nocatauth/gateway/bin/intel.rules.sh

  • and change permissions to a+x
  • /usr/share/nocatauth/gateway/bin/exception-portfwd.sh permit 10.11.19.99 00:04:23:48:7E:98 eth0 19931 5631 tcp
    /usr/share/nocatauth/gateway/bin/exception-portfwd.sh permit 10.11.19.12 00:06:25:1A:5E:57 eth0 11231 5631 tcp
    /usr/share/nocatauth/gateway/bin/exception-portfwd.sh permit 10.11.19.99 00:04:23:48:7E:98 eth0 19932 5632 udp
    /usr/share/nocatauth/gateway/bin/exception-portfwd.sh permit 10.11.19.12 00:06:25:1A:5E:57 eth0 11232 5632 udp

NOTE: This leads to extra rules that are redundant in order to allow tcp and udp to be set on the command line. The script needs to be reworked to fix.

D. Create new file /usr/share/nocatauth/gateway/bin/exception-portfwd.sh

  • and change permissions to a+x
  • ##
    # 02-14-03 dmz@dmzs.com
    # 02-16-03 dmz@dmzs.com - modified to work with host on specific interface
    # 07-30-03 dmz@dmzs.com - added inbound DNAT redirection from extport to dstport on specified host
    # 09-03-04 amj@personaltelco.net - added seventh option to support tcp|udp portfwd cmd line option
    #
    # eth0 is default outbound interface
    #
    # Set a permanent exception to the NoCat rules.
    #
    # This is useful to run at boot time, after you load the firewall
    # modules, but before bin/gateway runs.
    #
    # NOTE: To use elsewhere change the external ip for the nocat box in the script below. 
    #
    if [ -z "$1" -o -z "$2" -o -z "$3" -o -z "$4" ]; then
      echo "Usage:  $0 [permit|deny] [ host ] [ mac address ] [ eth ] [ extport ] [ dstport ] [ tcp|udp ]"
      echo
      echo "Adds a host + MAC to the exception list for NoCat.  Any machine"
      echo "specified by this utility won't have to login, and will be granted"
      echo "owner status."
      exit 1
    fi
    
    if [ "$1" = "permit" ]; then
      # Mangle packet for source IP & MAC, set to Owner level (MARK 1)
        echo iptables -t mangle -A PREROUTING -i $4 -m mac --mac-source $3 -s $2 -j MARK --set-mark 1
        iptables -t mangle -A PREROUTING -i $4 -m mac --mac-source $3 -s $2 -j MARK --set-mark 1
      # Insert at top of FORWARD filter to forward traffic for IP (masq handled by MARK) in $4 out eth0
        echo iptables -t filter -I FORWARD 1 -i $4 -s $2 -j ACCEPT
        iptables -t filter -I FORWARD 1 -i $4 -s $2 -j ACCEPT
        echo iptables -t filter -I FORWARD 1 -i eth0 -d $2 -j ACCEPT
        iptables -t filter -I FORWARD 1 -i eth0 -d $2 -j ACCEPT
      # Insert MASQ rule for permitted host
        echo iptables -t nat -I POSTROUTING 1 -o eth0 -s $2 -m mark --mark 1 -j MASQUERADE
        iptables -t nat -I POSTROUTING 1 -o eth0 -s $2 -m mark --mark 1 -j MASQUERADE
      # Insert port forwarding if in cmd line
        if [ "$5" ]; then
          iptables -t nat -I PREROUTING 1 -i eth0 -d 64.122.41.37 -p $7 --dport $5 -j DNAT --to-destination $2:$6
          echo iptables -t nat -I PREROUTING 1 -i eth0 -d 64.122.41.37 -p $7 --dport $5 -j DNAT --to-destination $2:$6
        fi
    elif [ "$1" = "deny" ]; then
      # Delete Mangle packet for source IP & MAC, set to Owner level (MARK 1)
      echo iptables -t mangle -D PREROUTING -i $4 -m mac --mac-source $3 -s $2 -j MARK --set-mark 1
        iptables -t mangle -D PREROUTING -i $4 -m mac --mac-source $3 -s $2 -j MARK --set-mark 1
      # Delete at top of FORWARD filter to forward traffic for IP (masq handled by MARK)
        echo iptables -t filter -D FORWARD -i $4 -s $2 -j ACCEPT
        iptables -t filter -D FORWARD  -s $2 -i $4 -j ACCEPT
       echo iptables -t filter -D FORWARD -i eth0 -d $2 -j ACCEPT
        iptables -t filter -D FORWARD -i eth0 -d $2 -j ACCEPT
      # Delete MASQ rule for permitted host
        echo iptables -t nat -D POSTROUTING -o eth0 -s $2 -m mark --mark 1 -j MASQUERADE
        iptables -t nat -D POSTROUTING -o eth0 -s $2 -m mark --mark 1 -j MASQUERADE
        if [ "$5" ]; then
          iptables -t nat -D PREROUTING -i eth0 -d 64.122.41.37 -p $7 --dport $5 -j DNAT --to-destination $2:$6
          echo iptables -t nat -D PREROUTING -i eth0 -d 64.122.41.37 -p $7 --dport $5 -j DNAT --to-destination $2:$6
        fi
    else
        echo "FATAL: Bad action: $action!"
        exit 1
    fi

E. Restart the services

  • /etc/init.d/dhcp restart  
    /etc/init.d/nocatauth-gateway restart

NoCatException (last edited 2007-11-23 18:01:12 by localhost)