/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ My particular situation is a bit different. In my little world, my firewall/router is dual-homed. Assume the external IP address (eth1) is 204.132.199.100. However, I had a number of aliases (eth1:1-eth1:8) that are aliases of the external address. For simplicity, jut assume that I have them set as 204.132.199.1-8, using a simple 24-bit class-c mask. Each alias is port forwarding a particular service to an internal host via ipmasqadm portfw. For instance, lets say that I have an internal host 10.1.1.1 that is a mail server. The objective is that outbound mail should LOOK like it's coming from the 204.132.199.1 address, so that DNS lookups and reply packets get handled correctly. I want all my inbound mail to get sent to the .1 address too, but that's a simple MX record which works fine. Inbound, everything is peachy. Outbound, everything seems normal too, EXCEPT..... ...all the outbound packets are MASQed as coming from the "real" external ip address (.100) instead of the alias that I want them to be MASQed as (.1) Apparently this problem requires the iproute2 solution, in order to do source address routing. I've asked Juanjo for confirmation, but haven't received a reply yet. I just don't like the idea of replacing my routing framework with an undocumented and semi-mysterious RPM from Russia.... If nobody in the MASQ, IPCHAINS, or IPMASQADM community is willing to discuss solutions that involve iproute2, then I don't think I want to stick my little fingers into it either! :>) The big disclaimer in the latest ipmasq howto seems to point to iproute2 to solve this sort of problem, but then says it won't work with MASQed addresses, and then says none of the gurus will answer questions about it. What I'm trying to reproduce is the same sort of IP address translation that is present in a Cisco PIX firewall, which uses the concept of a "conduit" between an internal host and an external host. You assign an external address from your Internet address space to an internal host, and then set up the address/ports/protocols of an Internet host that you want to communicate with. All outbound traffic appears to come from the assigned external address, so that replies are sent to the right firewall address. Port Forwarding on the "conduit" allows incoming packets of the particular specified combination into that internal host. Call me paranoid, but I have a number of services that I want to provide to external (internet-based) clients and partners, and I want each service/company to use a particular IP address instead of just globbing all the services into a single IP address. I DONT want to use multiple ethernet cards, because 8 addresses is just the beginning, and I'll run out of port density quickly. I DONT want to use multiple firewalls, because that's just harder to manage and inefficient. Does that clear up my context and intentions? Am I missing something obvious? It seems like a lot of people want to accomplish this same sort of thing.... I have to believe that Linux can do this, and it does seem to be a routing issue as opposed to a MASQ or IPCHAINS issue. Doug -----Original Message----- From: Gregory Leblanc [mailto:[EMAIL PROTECTED]] Sent: Thursday, December 09, 1999 2:47 PM To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED] Subject: Re: [Masq] binding particular IP addr to masq'd packets -- me too. [EMAIL PROTECTED] wrote: > > Any ideas guys? I meant to reply to this one if nobody else did, but I forgot, so I'll post some comments below. Briefly, I think that this is a config problem. > > INTERNET ------- Router A > | > 192.168.0.0/30 > | > Linux masq/router > | | | > | | | > 172.16.0.0/12 | | > | | > 216.174.15.192/26 | > | > 216.174.14.192/26 > > Here's my problem. I've got two public IP subnets that need to be routed > through the Linux masq/router to Router A and router A handles everything > from there. Also, Router A routes packets from the 172.16.0.0/12 subnet > to about 5 other subnets, one of which is a private subnet. That's all > fine and dandy. The only problem is that, when the Linux box masquerades > packets that are destined for someplace outside of my IP space, it will > translate all IP addresses to 192.168.0.2, which is the address of the > ethernet card which connects to Router A. Router A receives these packets > on 192.168.0.1 and deals with them then. So your masq/router has 4 interfaces, 172.16.0.0 MASK 255.240.0.0, 216.174.15.192 MASK 255.255.255.192, 216.174.14.192 MASK 255.255.255.192, and 192.168.0.0 MASK 255.255.255.252. (I had to translate those to something that I understand, I don't think binary anymore) The problem that you're having is that packets destined for an internet IP address, go through the 192.168.x.x interface, and get 192.168.0.2 address as the source. What is supposed to be MASQ'ed here? Seems to me that you should turn off masq for those machines, and just have the machine route those packets to the net, unless I'm missing something. Can you provide some more information on goals here? > > Obviously, nothing can be routed on the Internet with an IP from the > 192.168.0.0/16 network, so this isn't going to work. Does anyone know how > to make the Linux masq/router translate packet IP addrs to a particular > address, and THEN route them? Sure, you have it route them out an interface with that address, that's how masq works. The MASQ machine holds that IP address, and clients behind it seem to all be that machine to the outside world. _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
