Fedora Linux Support Community & Resources Center
  #1  
Old 25th January 2009, 04:21 PM
BlownCPU's Avatar
BlownCPU Offline
Registered User
 
Join Date: Dec 2007
Location: Gatwick, United Kingdom
Posts: 171
Unable to IP forward

I'm testing a friends (true story with true intentions... just in case I get flack over this) network his company network.

I am using arpwatch to detect arpspoofing but will be trying other tools out.

He wants to see if anyone is playing tricks on his LAN so I've been doing some reading and am using arpspoof to simulate an attacker. The arpspoof concept is familiar to me and I understand haow it works and what it does but one thing which I can't seem to do is to forward packets on my Linux Box and I'm wondering if I doing it correctly.

I would like to know if "echo 1 > /proc/sys/net/ipv4/ip_forward" is all I need to do to enable ip forwarding or do I need to issue another command along with this?

Does the kernel automatically take in the "1" as I hit enter?

The firewall is off just in case it was spoiling something along the line.

Network Manager is on, perhaps it is doing something it shouldn't and I should switch it off and set the card up manually?

I'm also working on a script for iptables which configures the firewall so that spoofing is not possible on each machine.

Any help greatly appreciated.

Blown CPU
__________________
.......and so the factory packed smoke had escaped !!
System: FC11 64bit, Asus P43 Pro, Intel E7400, 4G RAM, 30GB SSD drive with OS installed on it, 320GB HDD for storage, GeForce 9500GT, Broadcom Wifi NIC.
Reply With Quote
  #2  
Old 25th January 2009, 09:31 PM
Zotter's Avatar
Zotter Offline
Registered User
 
Join Date: May 2004
Location: Central Wyoming
Posts: 637
Quote:
Originally Posted by BlownCPU View Post

I would like to know if "echo 1 > /proc/sys/net/ipv4/ip_forward" is all I need to do to enable ip forwarding or do I need to issue another command along with this?

Does the kernel automatically take in the "1" as I hit enter?
Yes - that echo 1 line is all it takes to turn on IP forwarding in the kernel - it's instant.
Yes - there's more you need to do with Netfilter/Iptables to get IP forwarding working correctly and reasonably for your LAN. See the iptables tutorials/howtos for details.

For learning, the "Easy Firewall Generator" may be handy. Create the script and studying how it works while reviewing the tutorials and howtos is a great learning lab.
http://easyfwgen.morizot.net/

EDIT:
May want to take a look at this article as well
http://www.linuxsecurity.com/content/view/111337/169/
One issue talked about deals with source address verification in the kernel via: /proc/sys/net/ipv4/conf/all/rp_filter

EDIT-II:
NOTE: CONFIG_PROC_FS, CONFIG_SYSCTL and CONFIG_SYNCOOKIES are already compiled into Fedora (and most other popular distro) kernels by default
__________________
If it ain't broken - you're not really trying....
Registered Linux user #227845

Last edited by Zotter; 25th January 2009 at 09:48 PM.
Reply With Quote
Reply

Tags
forward, unable

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
I'm looking forward to Nix! adrianx Linux Chat 14 23rd December 2008 12:42 PM
help .forward talkstock888 Servers & Networking 0 22nd December 2005 06:12 PM
Unable to add forward map durwin Servers & Networking 0 29th June 2005 08:43 PM


Current GMT-time: 13:09 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat