/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


> > This all works fine BUT the internal machines can't access the port
> > forwarded machines on there external IP addresses.
> 
> That is true.  It's not exactly "forwarding" if a packet comes in one
> interface, and then leaves via the same interface.  That's called
> "botched networking", 'cause it's rather inefficient.  The main reason
> why it doesn't work, at least in the portfw case with which I'm
> familiar, is that port-forwarding works via masquerade rules, and when
> the packet comes in from an internal IP address, there is no matching
> masquerade (forwarding) rule, so a tunnel cannot be created for it.

I think this is a pretty big problem for MASQing in general. I would
certainly not bill it as "botched networking". I play a lot of online games.
As such, the local clients receive information from a remote service (not
DNS, for eg. Blizzard's Battle.net). Usually included in the stream is the
address of other game participants. Everything works fine via masq except
when you have two players behind the same masq wall that want to play
together. Since they get their address information from a remote host, it
usually refers to the external masq address. The machines then try to
address each other using the external addresses. Of course, games aren't the
only applications that do this, but they are closest to home for me.

Now, the purist would argue that you should write a module to rewrite the
packets. That's pretty foolish. There are tons of games out there and I
don't have time or desire to snoop their protocol. It would be much better
if masqing simply allowed you to refer to internal machines by the external
masq port AND have the outgoing packet MASQ'd (it is going out after all).
Yeah, it's inefficient, but I got horsepower and bandwidth to spare
(consider that machines are getting crazy fast and your internal lan is
usually going to be 10+x as fast as your external connection).

I would actually like to see a lot more flexibility in the MASQ support. I
should be able to do more than MASQ a packet. I should be able to write
rules to rewrite packets anyway that I want. It would allow people to get a
lot more applications to work without requiring us to write modules (which
totally blows).

In any case, I just wanted to kick in my two bits about using the external
ports from the inside.

        -rick

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to