/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



KD1CA - Dennis Lauzon <[EMAIL PROTECTED]> wrote:
>
> I have a gateway box set up which carries both my comercial address on
> eth0 and my local net(eth1) which is a subnet in ampr.org.  I wish be
> able to masq all outgoing packets except for 44.0.0.0/8.  All
> 44.0.0.0/8 should be routeed properly out the gateway through my TUNL0
> interface.  The tunl0 routing works fine until I turn on MASQ.

First of all, you must have your routes set up correctly, so that
traffic for the 44.* net is routed through your tunl0 interface, and all
other traffic is routed through your eth0 interface.  Ipchains does not
make routing policy decisions; that is for your route table to decide.
Ipchains performs only allow/deny/allow-with-masq decisions.

Next, you can set up ipchains rules that only masquerade traffic that is
being forwarded through your eth0 interface.

    ipchains -A forward -i eth0 -j MASQ

If necessary, you can also add a rule that simply permits the tunl0
traffic.

    ipchains -A forward -i tunl0 -j ACCEPT

Note that you might have some traffic that attempts to forward from your
eth0 interface to your tunl0 interface.  You should set up input rules
to filter out such traffic.

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to