Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] loopback into gentoo iptables
Date: Sun, 14 Oct 2007 22:25:17
Message-Id: 358eca8f0710141508ye4c0d7ey728a1e09c78444e6@mail.gmail.com
In Reply to: Re: [gentoo-user] loopback into gentoo iptables by Hans-Werner Hilse
1 On 05/10/2007, Hans-Werner Hilse <hilse@×××.de> wrote:
2 > Hi,
3 >
4 > On Fri, 5 Oct 2007 10:42:42 -0500
5 > "Walter Willis" <walterwn@×××××.com> wrote:
6 >
7 > > I have modem asdl zyxel 660 and activate loopback with command: "ip nat
8 > > loopback on"
9 >
10 > Where do you enter that and why? What is the thing _you_ call a
11 > loopback? On what device or machine does it exist? You don't seem to be
12 > talking about the "ifup" tool (since you talk about "ip", which however
13 > does not know the "nat" mode?!?), and you don't seem to be talking
14 > about the lo device either.
15 >
16 > > the ask is:
17 > > it is into gentoo linux with iptables ?
18 >
19 > Errm, again: What? Setting up you loopback device on gentoo is done
20 > automatically by /etc/init.d/net.lo. Should be run on bootup by rc,
21 > check "rc-update show".
22 >
23 > Setting up NAT works using a sysctl (or the procfs). Restricting the
24 > NAT works using iptables.
25 >
26 > > the compiler module especial for function?
27 >
28 > Errrr.... Again, not sure what you are asking here... Yes, you need
29 > kernel modules for both NAT to work and as well netfilter modules for
30 > the chains and targets and matches you want to use with iptables. They
31 > don't really have to be modules, you can compile them statically into
32 > the kernel as well.
33 >
34 > If unsure, rephrase your question -- and be a bit more verbose on what
35 > you intend to do... A bit more information might as well cure lack of
36 > proper vocabulary... Give examples, try to describe the setting.
37
38 My telepathic abilities are getting rusty these days, but if guessing
39 is allowed I think that the OP wanted to set up gentoo so that he
40 could access the Zyxel router's firewall and modify its rules, from
41 the Gentoo desktop. Either that, or he's thinking of building an
42 embedded image for Zyxel?!
43
44 More info would no doubt help. If not anything else, tell us what
45 Zyxel can and cannot do - if it allows ssh access to its OS, then you
46 may be able to set up firewall builder on the Gentoo box and use that
47 to access/setup the Zyxel firewall. If you are running OpenWRT (not
48 sure if this would run on Zyxel, but just don't stop me guessing now)
49 you should be able to cook something so that firewall builder could
50 hook into it.
51
52 Best of luck,
53 --
54 Regards,
55 Mick
56 --
57 gentoo-user@g.o mailing list