Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted (edited)

Hi there,

 

I hope someone can point me in the right direction here. All I'm attempting to do is set up Ubuntu Desktop 8.04 as a Transparent Proxy. I've done all the work on the proxy and that's working fine. I want to be able to communicate with the DNS Servers on eth0 from clients on the eth1 interface.

 

But I can't figure out how Ubuntu routes traffic :mad::)

 

Here's my test network:

 

Client PC 192.168.40.40/23 (DG: 192.168.30.3 DNS: 192.168.10.10)

l

L Ubuntu eth1 192.168.40.3/23

Ubuntu eth0 192.168.10.50/23 (DG: 192.168.10.1 DNS: 192.168.10.10)

l

L DNS Server 192.168.10.10

 

I've tried setting: net.ipv4.ip_forward=1 in /etc/sysctl.conf as I thought this should pass traffic forward.

 

I've looked at IP Tables but this looks just like a Firewall and not a router?

 

Any help would be great?

Edited by jimothy
Posted
I want to be able to communicate with the DNS Servers on eth0 from clients on the eth1 interface.

 

Do you need to run a DNS server on your filtering machine that deals with requests on eth1 and uses the DNS server available on eth0 as its parent server?

 

--

David Hicks

Posted

Thanks for the replies :)

 

@ dhicks. I thought about that, installing BIND, but I thought it may confuse matters more? If possible I could do that but how do I ensure that DNS is published on the eth1 interface and not on the eth0?

 

@CyberNerd: The routing table looks like this:

 

Kernel IP routing table

Destination Gateway Genmask Flags MSS Window irtt Iface

192.168.10.0 0.0.0.0 255.255.254.0 U 0 0 0 eth0

192.168.40.0 0.0.0.0 255.255.254.0 U 0 0 0 eth1

169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth1

0.0.0.0 192.168.10.1 0.0.0.0 UG 0 0 0 eth0

Posted

Kernel IP routing table

Destination Gateway Genmask Flags MSS Window irtt Iface

192.168.10.0 0.0.0.0 255.255.254.0 U 0 0 0 eth0

192.168.40.0 0.0.0.0 255.255.254.0 U 0 0 0 eth1

169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth1

0.0.0.0 192.168.10.1 0.0.0.0 UG 0 0 0 eth0

 

Shouldn't that second line be:

192.168.30.0 0.0.0.0 255.255.254.0 U 0 0 0 eth1

 

?

Posted

Yeah, should be. I changed the subnet which the eth1 was on as I've already got a VLAN on the eth0 side which is already on 192.168.30.0/23.

 

I wanted to ensure that there was no weird routing going on.

Posted
A default install of bind9 from the repo leaves it configured as a caching DNS server, just configure the forwarders.
Posted

Installed BIND9 and left as default. Configured DNS forwarders: 192.168.10.10.

 

Clients on the eth1 interface pick up DHCP with 192.168.40.3 as their DG and DNS server.

 

Still no DNS resolution for clients.

Posted

Not sure how to pull out BIND config, but if this is any help:

 

/etc/resolve.conf has: servername 192.168.10.10 specified.

 

I can dig 127.0.0.1 from the Ubuntu box and it shows it's using 192.168.10.10:53 to resolve the address.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...