/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ On Tue, 20 Jul 1999, Ed Harris wrote: > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ > > > > Hello > Been an avid linux user since...long ago (93/94), I subscribed to the masq > list archive, searched the masq archive, and swear I can't find what I'm > doing wrong. > Under Slakware kernel 2.0.36, had ip tunnelling set up, ipfwadm set up, so I > could masq to everywhere in the world except my offfice, which I tunnelled > to. (another 2.0.36 box there, lucky enuf to have a 8 ip subnet assigned to > me at home (RHIP ;-) ) > Under Slakware 2.2.5 kernel, using ipchains, I can't seem to tunnel to the > office anymore. Makes work at home on the (boo) NT network very unfriendly > - no domain logins, since my isp 'gives' me a firewall as part of the > deal... > Details: > ipchains -F > ipchains -X > ipchains -A forward -i eth1 -j MASQ > ipchains -A forward -i tunl0 -j ACCEPT > Eth0 is my internal, eth1 is my ISP (cable modem). > All comm works fine, even to my office, so then, I: > ifconfig tunl0 $localip up > route add -net $officenet netmask $mask gw $remotegw tunl0 > localip is my eth0 interface, officenet is my office subnet(duh), remotegw > is the linux box in the office > (still 2.0.36, but I've tried tunnelling to a 2.2.5 box there also, nothing > changed in the office, only change is the kernel @home. > tunl0 i'face never has anything but COLLISIONS(lots of them), have no comm > to/from the office. > Was I exporting some exotic bug in the 2.0.36 kerenel, or am I missing > something? > Thanks for ANY help or suggestions. > I recently ran into a similar problem using the tunl0 interface just after upgrading to kernel 2.2.x. Following is the info I found on another thread I subscribe to. Hope this helps with your issue as well! Dennis > >> Has anyone been able to sucessfully get IPIP encapsulation to work on a >> 2.2.x kernel? > > Yup. It's different than before. You need the new /sbin/ip tool to >configure tunnels. It is needed for a lot of other things too, like policy >routing, other tunnels, and ipv6... > >root@funk:/etc/rc.d#> cat rc.tun-up >#!/bin/bash > >echo "Configuring Amprnet IPIP tunneling...." >ifconfig tunl0 44.139.39.66 mtu 250 up > ># Amprnet routing... >ip route del 44.0.0.0/8 >ip route add 44.0.0.0/8 via 195.148.207.30 dev tunl0 onlink > > The onlink keyword is the important part. > >ftp.funet.fi:/pub/mirrors/ftp.inr.ac.ru/ip-routing/iproute2-current.tar.gz > > or directly from ftp.inr.ac.ru (usually slow). > > (btw, my machines are on the 6bone, and have AAAA records on the DNS. >Should enable apache and proftpd to talk ipv6 some day.) > > - Hessu > > _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/
