Solved

cheking TTL with the help of iptables...

Posted on 2004-03-22
6
322 Views
Last Modified: 2010-03-18
Hi U all

I've got a small problem (may be). I'm responsible for distributing an internet in a small LAN and now one problem occured to me. I want the netconnection, I'm offering to my clients, not to be possible for redistributing.

So, I'm using RED HAT 9.0 and my idea is by iptables to achieve my goal. It should be someting like this:
-----------------------------
iptables -t mangle -A OUTPUT -j TTL --ttl-set 1
-----------------------------
But it's a module what's the problem. I can't use the TTL without patching the kernel with the necessary module.

Is it possible to achieve my goal without recompiling the kernel? If yes (I hope), how?

10x for any help
0
Comment
Question by:gottin
  • 3
  • 3
6 Comments
 
LVL 40

Expert Comment

by:jlevie
Comment Utility
I'm not sure that I understand what you mean by "not to be possible for redistributing". Could you elaborate?
0
 

Author Comment

by:gottin
Comment Utility
well, it looks that it's not perfectly clear what I mean.
suppose the next topologi:           _       __
                                    |s|<--->|PC|
 ---------        -----------       |w|      --
|my server|<---->|client PC 1|<---->|i|<--->|PC|
 ---------        -----------       |t|      --
                                    |c|<--->|PC|
                                    |h|      --
                                     -
So, I want to configure "my server" this way that the PCs behind "client PC 1" do not have a network connectioning by simply setting the "client PC 1" as a firewall.

Tha question is: Is it possible to configure "my server" with the help of iptables (without recompiling the kernel)? If yes, how?

I hope it's clearer this time :)
0
 
LVL 40

Expert Comment

by:jlevie
Comment Utility
It sounds like you want to prevent a client from being able to set up a NAT'ing gateway and having multiple machines behind it. I don't believe that any sort of iptables rule is going to be able to detect or block this since the very nature of NAT means that all traffic, to an upstream node's view, will appear to be from/to the client IP. You might be able to infer that someone was doing this by traffic analysis, but even that gets iffy unless the volume is obviously much, much greater than could be generated by a single user.
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 

Author Comment

by:gottin
Comment Utility
well, the client PC are in most cases Windows machines and I think they are not able to use iptables. Well I just wanted to send the packets from my machine with TTL=1, so they can be alive not longer then the first PC, but after reading a bit bore I found that the onlies way to do this by the help of iptables is by patching the kernel and recompiling it.

So, I found my answer.

I want to close this question.

Thank U jlevie for trying to help.
0
 
LVL 40

Accepted Solution

by:
jlevie earned 150 total points
Comment Utility
I don't think that would help even if you did patch the kernel if someone was running a NAT'ing firewall on one of the windows boxes (ICS, WinGate, etc). The destination, as far as your Linux gateway is concerned, is the outside IP of such a system. The NAT'ing S/W is going to re-write the packet before passing it on to a system inside of the NAT'ing gateway and I think it will reset the TTL then.
0
 

Author Comment

by:gottin
Comment Utility
10x for helping me!

Stancho

Bulgaria
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now