/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


My particular situation is a bit different.  In my little world, my
firewall/router is dual-homed.  Assume the external IP address (eth1) is
204.132.199.100.  However, I had a number of aliases (eth1:1-eth1:8) that
are aliases of the external address.   For simplicity, jut assume that I
have them set as 204.132.199.1-8, using a simple 24-bit class-c mask.   Each
alias is port forwarding a particular service to an internal host via
ipmasqadm portfw.   

For instance, lets say that I have an internal host 10.1.1.1 that is a mail
server.   The objective is that outbound mail should LOOK like it's coming
from the 204.132.199.1 address, so that DNS lookups and reply packets get
handled correctly.   I want all my inbound mail to get sent to the .1
address too, but that's a simple MX record which works fine.   Inbound,
everything is peachy.   Outbound, everything seems normal too, EXCEPT.....

...all the outbound packets are MASQed as coming from the "real" external ip
address (.100) instead of the alias that I want them to be MASQed as (.1)

Apparently this problem requires the iproute2 solution, in order to do
source address routing.   I've asked Juanjo for confirmation, but haven't
received a reply yet.   I just don't like the idea of replacing my routing
framework with an undocumented and semi-mysterious RPM from Russia....  If
nobody in the MASQ, IPCHAINS, or IPMASQADM community is willing to discuss
solutions that involve iproute2, then I don't think I want to stick my
little fingers into it either! :>)   The big disclaimer in the latest ipmasq
howto seems to point to iproute2 to solve this sort of problem, but then
says it won't work with MASQed addresses, and then says none of the gurus
will answer questions about it.   

What I'm trying to reproduce is the same sort of IP address translation that
is present in a Cisco PIX firewall, which uses the concept of a "conduit"
between an internal host and an external host.   You assign an external
address from your Internet address space to an internal host, and then set
up the address/ports/protocols of an Internet host that you want to
communicate with.   All outbound traffic appears to come from the assigned
external address, so that replies are sent to the right firewall address.
Port Forwarding on the "conduit" allows incoming packets of the particular
specified combination into that internal host.

Call me paranoid, but I have a number of services that I want to provide to
external (internet-based) clients and partners, and I want each
service/company to use a particular IP address instead of just globbing all
the services into a single IP address.   I DONT want to use multiple
ethernet cards, because 8 addresses is just the beginning, and I'll run out
of port density quickly.   I DONT want to use multiple firewalls, because
that's just harder to manage and inefficient.

Does that clear up my context and intentions?   Am I missing something
obvious?   It seems like a lot of people want to accomplish this same sort
of thing....  I have to believe that Linux can do this, and it does seem to
be a routing issue as opposed to a MASQ or IPCHAINS issue.

Doug



-----Original Message-----
From: Gregory Leblanc [mailto:[EMAIL PROTECTED]]
Sent: Thursday, December 09, 1999 2:47 PM
To: [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]
Subject: Re: [Masq] binding particular IP addr to masq'd packets -- me
too.


[EMAIL PROTECTED] wrote:
> 
> Any ideas guys?

I meant to reply to this one if nobody else did, but I forgot, so I'll
post some comments below.  Briefly, I think that this is a config
problem.

> 
> INTERNET ------- Router A
>                    |
>              192.168.0.0/30
>                    |
>            Linux masq/router
>             |     |      |
>             |     |      |
>     172.16.0.0/12 |      |
>                   |      |
>       216.174.15.192/26  |
>                          |
>                 216.174.14.192/26
> 
> Here's my problem.  I've got two public IP subnets that need to be routed
> through the Linux masq/router to Router A and router A handles everything
> from there.  Also, Router A routes packets from the 172.16.0.0/12 subnet
> to about 5 other subnets, one of which is a private subnet.  That's all
> fine and dandy.  The only problem is that, when the Linux box masquerades
> packets that are destined for someplace outside of my IP space, it will
> translate all IP addresses to 192.168.0.2, which is the address of the
> ethernet card which connects to Router A.  Router A receives these packets
> on 192.168.0.1 and deals with them then.

So your masq/router has 4 interfaces, 172.16.0.0 MASK 255.240.0.0,
216.174.15.192 MASK 255.255.255.192, 216.174.14.192 MASK
255.255.255.192, and 192.168.0.0 MASK 255.255.255.252.  (I had to
translate those to something that I understand, I don't think binary
anymore)  The problem that you're having is that packets destined for an
internet IP address, go through the 192.168.x.x interface, and get
192.168.0.2 address as the source.  What is supposed to be MASQ'ed
here?  Seems to me that you should turn off masq for those machines, and
just have the machine route those packets to the net, unless I'm missing
something.  Can you provide some more information on goals here?

> 
> Obviously, nothing can be routed on the Internet with an IP from the
> 192.168.0.0/16 network, so this isn't going to work.  Does anyone know how
> to make the Linux masq/router translate packet IP addrs to a particular
> address, and THEN route them?

Sure, you have it route them out an interface with that address, that's
how masq works.  The MASQ machine holds that IP address, and clients
behind it seem to all be that machine to the outside world.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to