Wähle ich mich mit ppptp (scripts von Inode) ein und führe dann ein script mit iptables-commands aus ist alles ok. Wähle ich mich mit pppoe (config mit Suse-Yast) ein, ist direkt von der firewall aus auch alles ok, jedoch lassen sich einige Seiten von Rechnern dahinter nicht mehr ansprechen. Beim Zugriff der Seiten mittels proxy-server auf der firewall funktioniert es. Das script mit den firewall-regeln ist aber immer dasselbe.
Hat jemand eine Idee?
Mitprotokolliert der Zugriff auf www.psk.co.at:
pppoe (NAT von intern ĂĽber firewall):
- Code: Alles auswählen
Jan 3 11:18:28 firewall kernel: IN=eth1 OUT=dsl0 SRC=192.168.250.4 DST=194.107.107.112 LEN=47 TOS=0x00 PREC=0x00 TTL=127 ID=48475 DF PROTO=TCP SPT=1741 DPT=443 WINDOW=65535 RES=0x00 ACK PSH URGP=0
Jan 3 11:18:28 firewall kernel: IN=eth1 OUT=dsl0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=48476 DF PROTO=TCP SPT=1741 DPT=443 WINDOW=65535 RES=0x00 ACK FIN URGP=0
Jan 3 11:18:28 firewall kernel: IN=dsl0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=9373 PROTO=TCP SPT=443 DPT=1741 WINDOW=0 RES=0x00 RST URGP=0
Jan 3 11:18:30 firewall kernel: IN=eth1 OUT=dsl0 SRC=192.168.250.4 DST=194.107.107.112 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=48489 DF PROTO=TCP SPT=1747 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 11:18:30 firewall kernel: IN=dsl0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=44 TOS=0x00 PREC=0x00 TTL=58 ID=59569 DF PROTO=TCP SPT=443 DPT=1747 WINDOW=8760 RES=0x00 ACK SYN URGP=0
Jan 3 11:18:30 firewall kernel: IN=eth1 OUT=dsl0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=48490 DF PROTO=TCP SPT=1747 DPT=443 WINDOW=65535 RES=0x00 ACK URGP=0
Jan 3 11:18:30 firewall kernel: IN=eth1 OUT=dsl0 SRC=192.168.250.4 DST=194.107.107.112 LEN=106 TOS=0x00 PREC=0x00 TTL=127 ID=48491 DF PROTO=TCP SPT=1747 DPT=443 WINDOW=65535 RES=0x00 ACK PSH URGP=0
Jan 3 11:18:33 firewall kernel: IN=eth1 OUT=dsl0 SRC=192.168.250.4 DST=194.107.107.112 LEN=106 TOS=0x00 PREC=0x00 TTL=127 ID=48520 DF PROTO=TCP SPT=1747 DPT=443 WINDOW=65535 RES=0x00 ACK PSH URGP=0
Jan 3 11:18:33 firewall kernel: IN=dsl0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=44237 DF PROTO=TCP SPT=443 DPT=1747 WINDOW=8694 RES=0x00 ACK URGP=0
pppoe (via proxy auf der firewall):
- Code: Alles auswählen
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=26380 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=5808 RES=0x00 SYN URGP=0
Jan 3 11:20:10 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=44 TOS=0x00 PREC=0x00 TTL=59 ID=26046 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=8712 RES=0x00 ACK SYN URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=26381 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=5808 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=106 TOS=0x00 PREC=0x00 TTL=64 ID=26382 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=5808 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:10 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=1492 TOS=0x00 PREC=0x00 TTL=59 ID=48830 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=8646 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=26383 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=8712 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=1492 TOS=0x00 PREC=0x00 TTL=59 ID=49086 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=8646 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=26384 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=11616 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=199 TOS=0x00 PREC=0x00 TTL=59 ID=64958 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=8646 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=26385 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=14520 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=179 TOS=0x00 PREC=0x00 TTL=64 ID=26386 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=14520 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=46 TOS=0x00 PREC=0x00 TTL=64 ID=26387 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=14520 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:10 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=40 TOS=0x00 PREC=0x00 TTL=59 ID=24255 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=8501 RES=0x00 ACK URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=81 TOS=0x00 PREC=0x00 TTL=64 ID=26388 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=14520 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:10 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=87 TOS=0x00 PREC=0x00 TTL=59 ID=17344 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=8460 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:10 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=621 TOS=0x00 PREC=0x00 TTL=64 ID=26389 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=14520 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:11 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=885 TOS=0x00 PREC=0x00 TTL=59 ID=45504 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=7879 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=67 TOS=0x00 PREC=0x00 TTL=64 ID=26390 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=17424 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=26391 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=17424 RES=0x00 ACK FIN URGP=0
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=195.58.160.194 LEN=61 TOS=0x00 PREC=0x00 TTL=64 ID=44070 DF PROTO=UDP SPT=32799 DPT=53 LEN=41
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=195.58.160.194 LEN=61 TOS=0x00 PREC=0x00 TTL=64 ID=44074 DF PROTO=UDP SPT=32800 DPT=53 LEN=41
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=195.58.160.194 LEN=61 TOS=0x00 PREC=0x00 TTL=64 ID=44077 DF PROTO=UDP SPT=32801 DPT=53 LEN=41
Jan 3 11:20:11 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=67 TOS=0x00 PREC=0x00 TTL=59 ID=64960 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=7852 RES=0x00 ACK PSH URGP=0
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=3726 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=0 RES=0x00 RST URGP=0
Jan 3 11:20:11 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=40 TOS=0x00 PREC=0x00 TTL=59 ID=1473 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=7852 RES=0x00 ACK FIN URGP=0
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=3727 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=0 RES=0x00 RST URGP=0
Jan 3 11:20:11 firewall kernel: IN=dsl0 OUT= MAC= SRC=194.107.107.112 DST=81.223.97.105 LEN=40 TOS=0x00 PREC=0x00 TTL=59 ID=6593 DF PROTO=TCP SPT=443 DPT=32826 WINDOW=7852 RES=0x00 ACK URGP=0
Jan 3 11:20:11 firewall kernel: IN= OUT=dsl0 SRC=81.223.97.105 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=3728 DF PROTO=TCP SPT=32826 DPT=443 WINDOW=0 RES=0x00 RST URGP=0
Jan 3 11:20:11 firewall kernel: IN=dsl0 OUT= MAC= SRC=195.58.160.194 DST=81.223.97.105 LEN=162 TOS=0x00 PREC=0x00 TTL=62 ID=0 DF PROTO=UDP SPT=53 DPT=32799 LEN=142
ppptp:
- Code: Alles auswählen
Jan 3 11:22:03 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=51240 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 11:22:03 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=44 TOS=0x00 PREC=0x00 TTL=58 ID=46652 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8760 RES=0x00 ACK SYN URGP=0
Jan 3 11:22:03 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=51241 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=65535 RES=0x00 ACK URGP=0
Jan 3 11:22:03 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=138 TOS=0x00 PREC=0x00 TTL=127 ID=51242 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=65535 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:03 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=29246 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8662 RES=0x00 ACK URGP=0
Jan 3 11:22:03 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=166 TOS=0x00 PREC=0x00 TTL=58 ID=57409 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8662 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:03 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=46 TOS=0x00 PREC=0x00 TTL=127 ID=51247 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=65409 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=49987 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8656 RES=0x00 ACK URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=662 TOS=0x00 PREC=0x00 TTL=127 ID=51248 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=65409 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=885 TOS=0x00 PREC=0x00 TTL=58 ID=59204 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8034 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=67 TOS=0x00 PREC=0x00 TTL=127 ID=51253 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=64564 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=51254 DF PROTO=TCP SPT=1762 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=51255 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=64564 RES=0x00 ACK FIN URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=44 TOS=0x00 PREC=0x00 TTL=58 ID=23365 DF PROTO=TCP SPT=443 DPT=1762 WINDOW=8760 RES=0x00 ACK SYN URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=51256 DF PROTO=TCP SPT=1762 DPT=443 WINDOW=65535 RES=0x00 ACK URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=138 TOS=0x00 PREC=0x00 TTL=127 ID=51257 DF PROTO=TCP SPT=1762 DPT=443 WINDOW=65535 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=24133 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8007 RES=0x00 ACK URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=67 TOS=0x00 PREC=0x00 TTL=58 ID=32325 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8007 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=51258 DF PROTO=TCP SPT=1761 DPT=443 WINDOW=0 RES=0x00 ACK RST URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=32581 DF PROTO=TCP SPT=443 DPT=1761 WINDOW=8007 RES=0x00 ACK FIN URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=51259 PROTO=TCP SPT=1761 DPT=443 WINDOW=0 RES=0x00 RST URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=46663 DF PROTO=TCP SPT=443 DPT=1762 WINDOW=8662 RES=0x00 ACK URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=166 TOS=0x00 PREC=0x00 TTL=58 ID=32073 DF PROTO=TCP SPT=443 DPT=1762 WINDOW=8662 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=46 TOS=0x00 PREC=0x00 TTL=127 ID=51260 DF PROTO=TCP SPT=1762 DPT=443 WINDOW=65409 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=1612 DF PROTO=TCP SPT=443 DPT=1762 WINDOW=8656 RES=0x00 ACK URGP=0
Jan 3 11:22:04 firewall kernel: IN=eth1 OUT=ppp0 SRC=192.168.250.4 DST=194.107.107.112 LEN=810 TOS=0x00 PREC=0x00 TTL=127 ID=51265 DF PROTO=TCP SPT=1762 DPT=443 WINDOW=65409 RES=0x00 ACK PSH URGP=0
Jan 3 11:22:04 firewall kernel: IN=ppp0 OUT=eth1 SRC=194.107.107.112 DST=192.168.250.4 LEN=1500 TOS=0x00 PREC=0x00 TTL=58 ID=55884 DF PROTO=TCP SPT=443 DPT=1762 WINDOW=7886 RES=0x00 ACK URGP=0