PDA

View Full Version : pppoe, smoothwall, showeq. huh?



reklar
04-28-2002, 01:12 AM
Hey all, seeking guidance on getting the following setup to work.
ADSL using pppoe comes into a linux based dedicated firewall (smoothwall) then that box and the 2 clients (win2k(eq) and RH7.2(seq)) all connect to a netgear hub. All nics are same model netgear, however i'm *not* sure they can go into promoiscuous mode. The hub has 'normal' mode or 'uplink' mode, got it running in normal at the moment. Smoothwall uses pppoe, which i know showeq won't read, but i am wondering if anyone knows whether smoothwall can be configured to use an adsl line and pass the packets through to the lan as tcp/ip.
Also, the win2k box can see the RH box, but not vice versa. smoothwall can see both, and both can see smoothwall. Net access works on both, but when eq is running showeq picks up no packets. (pppoe obviously).
Also, is there anywhere i can find out whether my NIC supports promiscuity or not?

Any info about how i might be able to get this work,or anyone's experiences/resources for seq+smoothwall would be greatly appreciated.

Thx,
Reks

edit: bah spelling

Ratt
04-28-2002, 01:29 AM
First and foremost, if your SEQ box and your EQ box are on different segments, it would be an utter nightmare trying to make it work. The SEQ and EQ box must either both be on GREEN or ORANGE.

I'm going to assume both your SEQ and EQ box are on your GREEN network. That being the case, they are using TCP/IP and probably have a 192.168.0.x or 192.168.1.x ip address. I will work off this assumption.

From what I can understand of your message, and please correct me if I'm wrong, you have your ADSL line going into your RED nic on the smoothie box. You then have your GREEN nic going into a hub, and your SEQ and EQ boxes connected to that hub, yes?

If that is the case, then you should have no problems. First ping the SEQ box from the EQ box, then ping the EQ box from the SEQ box. Assuming you can ping, try running tcpdump on the SEQ box while you are playing EQ on the EQ box and see if you see the packets going back and forth.

Basically, if you have your SEQ and EQ box on the GREEN NIC, you need to search around for the normal TCP/IP troubleshooting and figure out what the problem is from there.

If your setup is different, please detail what you have specifically.

Last, but not least ... dump that crusty Smoothie and use IPCop (http://www.ipcop.org), which was based off of Smoothwall, but it's run by people who are a hell of a lot nicer and it's totally GPL'd. If you are famaliar with Smoothwall, you'll have ZERO trouble with IPCop.

fryfrog
04-29-2002, 12:17 AM
do you use IPCop ratt? i actually downloaded and tried it out mostly because you (and thus these forums) recommended it. i liked it except for ONE little thing. i had a hell of a time using my 2x 3c509b's with it.

when i had them both in, no matter what i tried it would always detect my "LAN" nic as my RED nic and my "INTERNET" nic as my GREEN nic. normally i wouldn't think this would be much of a problem, but for me my cable modem is bound to the MAC addy of the INET nic.

i tried swapping their positions (sometimes that works with isa). i looked for an easy way to swap eth0/eth1 and found it in /var/ipcop/ethernet/settings. i swapped them and it all seemed to work great except for dhcp server seems hardwared to start on eth0.

so, i swap them BACK (even though position didn't do anything) and then i used a 3com util to swap their physical io and irq. it successfully swapped them all right, but IPCop STILl insisted on using the INET nic as the "GREEN" nic.

anyway, i gotta goto bed now and i'll read about IPCop some while i'm at work... but i'd be open to any helpful suggestions :)

i keep ending back up on my freesco setup which is old and runs kernel 2.0.38. i was really looking forward to the snort and the nice gui web interface ;)

fryfrog
04-29-2002, 12:22 AM
**I think i found my own fix, i'll try this tomorow :)

Configuring 3C509B-TPO ISA NICs
1) set cards to use address of 0x200, 0x240, 0x280, 0x2c0, 0x300, 0x340, 0x380, 0x3c0. -- this is for any type of ISA NIC - some drivers allow the ones between, but this is a safe method.

2) Do not use PROBE, choose SELECT - you can try using the 3c509 and normally will work...

If not use MANUAL and use 3c509.o irq=A,B,C io=0xAAA,0xBBB,0xCCC where A AAA are for the first card...

If it did not take... turn off the computer and try again.

3) once it takes - complete the setup and reboots - besure to turn off and on the power. (do it during the POST)

Durng the boot WATCH and besure the cards are detected. If you get insmod 3c509.o is missing, then vi /var/ipcop/ethernet/settings and find the first 3c509.o and remove ".o". Save and reboot - again besure to power off and on.

3c509 has a problem during softboot. the second and third cards will not be detected unless you cycle the power. - this is problem going back to pre-Redhat 6.2