I don't know if this functionality can be accommodated by IPCHAINS/IPMASQADM
but here it goes.

I have six machines in the following config

Machine 1 (167.16.1.30/31)
|
|       Machine 2 (167.16.1.100)
|       |
|       |       Machine 3 (167.16.1.101)
|       |       |
|       |       |       Machine 4 (167.16.1.102)
|       |       |       |
|       |       |       |       Machine 5 (167.16.1.103)
|       |       |       |       |
|       |       |       |       |       Machine 6 (167.16.1.104)
|       |       |       |       |       |
|_______|_______|_______|_______|_______|_______

Machine 1 is Linux RH 5.2 (kernel 2.2.9;IPChains 1.3.9) with two interfaces
(30/31).  All  machines have connectivity with each other and with this
internet (not that that matters).   What I desire to do (actually the
problem is larger than this but this is vastly simplified) is  make Machine
1 the access point for all FTP, WWW, , telnet, etc for the LAN.

For instance of a client on Machine 6 opens a telnet session to Machine 1
then they would get  transparently redirected to Machine 2 for instance.

Here is what I got on the chains machine:

[root@linux01 /]# ipchains -L
Chain input (policy ACCEPT):
Chain forward (policy DENY):
target     prot opt     source                destination           ports
MASQ       all  ------  167.16.1.30/24       anywhere              n/a
MASQ       all  ------  anywhere             167.16.1.30/24        n/a
MASQ       all  ------  167.16.1.31/24       anywhere              n/a
MASQ       all  ------  anywhere             167.16.1.31/24        n/a
Chain output (policy ACCEPT):

And:

[root@linux01 /]# ipmasqadm portfw -l
prot localaddr            rediraddr               lport    rport  pcnt  pref
TCP  167.16.1.30        167.16.1.100              telnet   telnet   10    10

This doesn't work at all.
 I even tried it with ONE NIC and had no luck as well.

Can anyone point me in the right direction?  I believe the problem has
something to do with the fact that MASQed packets still look like they are
coming from the original source.  So during the previous example, Machine 2
thinks that it has a telnet session with Machine 6 even though its supposed
to be going though the CHAINS machine 1.  The return packets actually have a
direct path to the client bypassing the MASQ on return.  I don't know what
effect this has on it but it may be a problem.

Thanks for any help you can give!

-------------------------------------------
Provided to you by Matt Hrynkow




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to