/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Here's a different situation for you -- one of my clients originally had 
a block of 64 "real" ip addresses on a DSL circuit.  They wanted to 
move to a masq firewall, partly to have the firewall, partly because 
the ISP wanted some of his addresses back.  So, I built them a 
Linux firewall.  

So, the client is afraid to make the big switchover, and connects 
both eth0 (internal, 192.168.1.0/24) and eth1 (external, 204...) to 
the network, and re-addresses his workstations a few at a time.  
This obviously isn't desirable, but it seemed to work.  Recently, I 
changed the firewall script from a simple masq, to a stronger one.  
The PCs were fine, the Macintoshes suddenly couldn't get through 
the gateway, with the strong script.  I see in my log, on the Linux 
gateway, rejected attempts by some of the stations to access the 
192 network through eth1, which is the external card.  Any idea 
what's happening?  It seems to be just the Macs -- recent version 
of MacOs.

It would all be solved if the client would get bold and separate the 
internal and external networks, but that may not happen for a while. 
One guy at the site has to support about 60 stations, and think he 
can't be down.  If we had done this all at installation time, we could 
have done it right the first time.  Oh well.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to