I don't know if this functionality can be accommodated by IPCHAINS/IPMASQADM but here it goes. I have six machines in the following config Machine 1 (167.16.1.30/31) | | Machine 2 (167.16.1.100) | | | | Machine 3 (167.16.1.101) | | | | | | Machine 4 (167.16.1.102) | | | | | | | | Machine 5 (167.16.1.103) | | | | | | | | | | Machine 6 (167.16.1.104) | | | | | | |_______|_______|_______|_______|_______|_______ Machine 1 is Linux RH 5.2 (kernel 2.2.9;IPChains 1.3.9) with two interfaces (30/31). All machines have connectivity with each other and with this internet (not that that matters). What I desire to do (actually the problem is larger than this but this is vastly simplified) is make Machine 1 the access point for all FTP, WWW, , telnet, etc for the LAN. For instance of a client on Machine 6 opens a telnet session to Machine 1 then they would get transparently redirected to Machine 2 for instance. Here is what I got on the chains machine: [root@linux01 /]# ipchains -L Chain input (policy ACCEPT): Chain forward (policy DENY): target prot opt source destination ports MASQ all ------ 167.16.1.30/24 anywhere n/a MASQ all ------ anywhere 167.16.1.30/24 n/a MASQ all ------ 167.16.1.31/24 anywhere n/a MASQ all ------ anywhere 167.16.1.31/24 n/a Chain output (policy ACCEPT): And: [root@linux01 /]# ipmasqadm portfw -l prot localaddr rediraddr lport rport pcnt pref TCP 167.16.1.30 167.16.1.100 telnet telnet 10 10 This doesn't work at all. I even tried it with ONE NIC and had no luck as well. Can anyone point me in the right direction? I believe the problem has something to do with the fact that MASQed packets still look like they are coming from the original source. So during the previous example, Machine 2 thinks that it has a telnet session with Machine 6 even though its supposed to be going though the CHAINS machine 1. The return packets actually have a direct path to the client bypassing the MASQ on return. I don't know what effect this has on it but it may be a problem. Thanks for any help you can give! ------------------------------------------- Provided to you by Matt Hrynkow _______________________________________________ Masq maillist - [EMAIL PROTECTED] http://tiffany.indyramp.com/mailman/listinfo/masq Admin requests can be handled by web (above) or [EMAIL PROTECTED]
