Re: Help REQ: 2-way NAT Problem

From: Edward Paul Wehrwein (last_name_at_ccs.neu.edu)
Date: 12/11/03

  • Next message: jpd: "Re: on home firewall for OpenBSD novice"
    Date: Thu, 11 Dec 2003 02:45:17 -0500
    
    

    "NoNameHere" <recpharm@hotmail.com> wrote in message
    news:ee7698ab.0312102326.60227e17@posting.google.com...
    > System: OpenBSD 3.4 on a i386 type of box.
    >
    > I would like to have RDP work for 2 hosts inside my network.
    >
    > Host 1: 192.168.1.1
    > Host 2: 192.168.1.2
    >
    > The following works great for host 1:
    > rdr on $ext_dev proto tcp from any to any port 3389 -> 192.168.1.15
    > port 3389
    >
    > How can I setup my firewall to do the following:
    > - rdr port 3390 from the internet to 3389 on Host 2
    > - rdr port 3389 from Host 2 to port 3390 on the internet?
    >
    > It looks like I need both a RDR statement and a NAT statement, but
    > none of my combinations have worked. Any ideas?
    >
    > TIA

    I'm not sure that there's a good way to do what you're looking for, but
    since you're messing with ports anyway why not change the remote desktop
    listening port. There is info on how that can be done here:
    http://www.computing.net/windows2003/wwwboard/forum/788.html

    Hope that helps.


  • Next message: jpd: "Re: on home firewall for OpenBSD novice"

    Relevant Pages

    • Re: SSO fails when machine is connected to network
      ... I added an entry to both the hosts and lmhosts files and I ... (this message came when I tried to delete the receive port to add it again) ... I have a named workgroup using the name of the machine. ... network adapter or add another explicit loopback) that is not 127.0.0.1. ...
      (microsoft.public.biztalk.server)
    • Re: Application to check the Internet status??
      ... not working if target address is not within the same network. ... capabilities to reach various hosts by various protocols. ... What do you mean by "internet status"? ... "can I connect to port 80 at www.google.com", fine, test for that. ...
      (comp.unix.programmer)
    • Port Scan(?)
      ... On my 10.1.2.0/24 network, I discovered (with ... Ethereal) that one of my hosts was ... broadcasting UDP packets to 255.255.255.255 to port ... The *source port* though was incrementing by one after ...
      (Security-Basics)
    • Re: Discovering Live Hosts
      ... Yes, arp spoofing, and port monitoring as well, will ... only show you traffic on your current network, ... range in communication with hosts on your LAN; ... firewall. ...
      (Pen-Test)
    • Re: Question on keeping Fedora 7 secure while connected to Internet
      ... to disable relaying from untrusted hosts). ... Telnet is available to two specific hosts only, ... The password guessing programs all ... attack port 22 so using a different port makes you invisible to them. ...
      (comp.os.linux.security)