WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] NET Network / Server running on internal Network not rea

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] NET Network / Server running on internal Network not reachable
From: Robert M. Münch <robert.muench@xxxxxxxxxxxxxxx>
Date: Wed, 09 Jul 2008 20:08:32 +0200
Delivery-date: Wed, 09 Jul 2008 11:10:18 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <4bca5f6c0807081934l5f9869bfjf9a430bbae293ef5@xxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <op.udzlyre33b5602@robby-laptop> <4873DFDA.2040808@xxxxxxxxx> <4bca5f6c0807081934l5f9869bfjf9a430bbae293ef5@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Opera Mail/9.50 (Win32)
On Wed, 09 Jul 2008 04:34:01 +0200, Christopher Isip <cmisip@xxxxxxxxx> wrote:

The easiest way to do IP masquerade is with shorewall.  Try the two
interface configuration with one interface the external and the other the
internal/bridged interface.

Hi Chris, I took a look into shorewall. I followed the information to setup a simple Xen system. But it doesn't work. I can't connect to the web-server. I always get a "conneciton refused".

Here is some output from the logging and TCPDUMP:


HTTP from DMZ/10.0.0.1 (wget www.robertmuench.de)
Jul 9 16:16:29 FORWARD:REJECT:IN=vif3.0 OUT=eth0 SRC=10.0.0.1 DST=87.118.120.128 LEN=65 TOS=0x00 PREC=0x00 TTL=63 ID=56283 DF PROTO=UDP SPT=32768 DPT=53 LEN=45

Here I tracked a wget 87.118.120.16 So the requests comes in but is immediatly answered with something that rejects/refuses the connection to be established. Error message on the requester: connection refused.


root@eisxen:~/shorewall-config# tcpdump -i eth0 host 62.141.54.100 and port 80
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 68 bytes
16:42:23.415056 IP ns.km1428.keymachine.de.54159 > eisxen.www: S 2049446876:2049446876(0) win 5840 <mss 1460,sackOK,timestamp 2303776659[|tcp]> 16:42:23.416084 IP eisxen.www > ns.km1428.keymachine.de.54159: R 0:0(0) ack 2049446877 win 0


In which mode do I need to run XEN, bridged, routed, nat? I have tried birdged and nat. Same effect, doesn't work.

Best regards.

--
Robert M. Münch
http://www.robertmuench.de

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users