Author Topic: Ping Outside from inside  (Read 2425 times)

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Ping Outside from inside
« on: June 08, 2008, 04:02:09 pm »
I`ve insalled ebox and is using the proxy for my network connections and this setup works perfectly but none of the pc`s can use telnet ot ping any connection behond the server can anyone help me to configure this correctly ? I know its got something to do with the proxy settings because the server itself can ping and lookup hosts via the GUI but im a bit new so i need to sharpen up on this matter any help would be greatly appriciated Thanx!!!!!! ;)
Only people that wants to no more will ask!!

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: Ping Outside from inside
« Reply #1 on: June 09, 2008, 09:26:55 am »
In theory ICMP traffic is not filtered, so ping should work nicely. Once you set up eBox as gateway (at least one external and one internal interface) you're doing NAT and firewall is filtering almost any traffic to secure your LAN.

Every traffic flow you may allow to your LAN (except for Web connections which proxy handles them), you must set rules in "Filtering rules for internal networks" section in Firewall module.

Hope this helps.
My secret is my silence...

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: Ping Outside from inside
« Reply #2 on: June 12, 2008, 10:14:58 pm »
I`ve set my ETH0 witch connects to my router on external and created a rule for internal networks in firewall/packet filter to allow all just to check if it works and no success any idea what im doing wrong coz i know its possible ive seen guys ping google or any site on theyr pc`s throug a ebox server but i mus ad it was a older version of ebox 0.10 or something ! is that not mabe the problem that this version was`nt configured to do that? ???
Only people that wants to no more will ask!!

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: Ping Outside from inside
« Reply #3 on: June 13, 2008, 09:08:52 am »
Which eBox version are you using?

As I said above, ICMP traffic is not filtered at all. So the main problem should be the routing. They may know how to reach the destination but not how to come back...
My secret is my silence...

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: Ping Outside from inside
« Reply #4 on: June 13, 2008, 02:36:44 pm »
I`m using GNU ebox ver 0.11.99 the newest I know thusfar!!!

Only people that wants to no more will ask!!

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: Ping Outside from inside
« Reply #5 on: July 02, 2008, 11:06:54 pm »
Okay I am still struggling with this I know now what it is you were talking about but call me stupid I cannot fix it could you please give me some guidelines as to how its done or jus the starting point ?? please


Hannes
Only people that wants to no more will ask!!

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: Ping Outside from inside
« Reply #6 on: July 03, 2008, 08:40:22 am »
Have you set up the default gateway through "Network->Gateways"?

Nothing related to the firewall since ICMP traffic is not filtered at all...
My secret is my silence...

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: Ping Outside from inside
« Reply #7 on: July 03, 2008, 08:07:35 pm »
Hey sixstone and Yes i have created a default gateway otherwise my proxy does not work at all and Ive created objects with its relevant members and the proxy works fine but still cant ping anything accept the server itself not ping or telnet works! I feel so stupid coz i know its something small Ive overlooked again but cant find it yet! any help would be greatly appreciated

Thanx in advance
Only people that wants to no more will ask!!