/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Here is a thought, though I have not had the opportunity to test it, that may help your situation. If you test this please post your results, I would be very interested. I can't test it at home because I only have 1 IP. I am going to be setting up a firewall at work soon in a situation similar to yours, so I am interested if this will work. As I understand it, it should. Couldn't you specify a source and a destination address in your IPCHAINS rules? Something like: First setup your IP alies on eth1. Then in your rc.firewall rules (or where ever you are putting them): #incoming rules ipchains -F input ipchains -P input REJECT #I am assuming eth0 is your nic for your internal 10.1.x network ipchians -A input -i eth0 -s 10.1.1.0/24 -d 0.0.0.0/0 -j ACCEPT #no spoofing ipchains -A input -i eth1 -s 10.1.1.0/24 -d 0.0.0.0/0 -j REJECT ipchains -A input -i eth1 -s 10.1.1.1/24 -d 204.132.199.1/24 -j ACCEPT ipchains -A input -i eth1 -s 10.1.1.2/24 -d 204.132.199.2/24 -j ACCEPT ipchains -A input -i eth1 -s 10.1.1.3/24 -d 204.132.199.3/24 -j ACCEPT ipchains -A input -i eth1 -s 10.1.1.4/24 -d 204.132.199.4/24 -j ACCEPT ipchains -A input -i lo -s 0/0 -d 0/0 -j ACCEPT ipchains -A input -s 0/0 -d 0/0 -l -j REJECT #Outgoing ipchains -F output ipchains -P output REJECT ipchains -A output -i eth0 -s 0/0 -d 10.1.1.0/24 -j ACCEPT ipchains -A output -i eth1 -s 0/0 -d 10.1.1.0/24 -l -j REJECT ipchains -A output -i eth1 -s 10.1.1.0/24 -d 0/0 -l -j REJECT ipchains -A output -i eth1:1 -s 204.132.199.1/24 -d 0/0 -j ACCEPT ipchains -A output -i eth1:2 -s 204.132.199.2/24 -d 0/0 -j ACCEPT ipchains -A output -i eth1:3 -s 204.132.199.3/24 -d 0/0 -j ACCEPT ipchains -A output -i eth1 -s 204.132.199.4/24 -d 0/0 -j ACCEPT ipchains -A output -i lo -s 0/0 -d 0/0 -j ACCEPT ipchains -A output -s 0/0 -d 0/0 -l -j REJECT #Forwarding #flush portfw ipmasqadm portfw -f #forward mail addresses ipmasqadm portfw -a -P tcp -L 204.132.199.1 25 -R 10.1.1.1 25 ipmasqadm portfw -a -P tcp -L 204.132.199.1 110 -R 10.1.1.1 110 #forward WWW ipmasqadm portfw -a -P tcp -L 204.132.199.2 80 -R 10.1.1.2 80 #forward LDAP ipmasqadm portfw -a -P tcp -L 204.132.199.3 389 -R 10.1.1.3 389 #handle the forwarding and MASQing of above services ipchains -A forward -s 10.1.1.1/24 -i eth1:1 -d 204.132.199.1/24 -j MASQ ipchains -A forward -s 10.1.1.2/24 -i eth1:2 -d 204.132.199.2/24 -j MASQ ipchains -A forward -s 10.1.1.3/24 -i eth1:3 -d 204.132.199.3/24 -j MASQ #handle forwarding and MASQing for others. I think this will forward everything else that doesn't match the above. ipchains -A forward -s 10.1.1.0/24 -i eth1 -d 204.132.199.4/24 -j MASQ #reject everything else ipchains -A forward -s 0/0 -d 0/0 0. -j REJECT I'm sure you will want to add to add other things to it, but I think this would be the bulk of it. Let me know if this works for you I would be very interested. -- Daniell Freed Computer Services Dewitt, Ross, & Stevens He who fights with monsters might take care lest he thereby become a monster. And if you gaze for long into an abyss, the abyss gazes also into you. Beyond Good and Evil Friedrich Wilhelm Nietzche [EMAIL PROTECTED] wrote: > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ > > My particular situation is a bit different. In my little world, my > firewall/router is dual-homed. Assume the external IP address (eth1) is > 204.132.199.100. However, I had a number of aliases (eth1:1-eth1:8) that > are aliases of the external address. For simplicity, jut assume that I > have them set as 204.132.199.1-8, using a simple 24-bit class-c mask. Each > alias is port forwarding a particular service to an internal host via > ipmasqadm portfw. > > For instance, lets say that I have an internal host 10.1.1.1 that is a mail > server. The objective is that outbound mail should LOOK like it's coming > from the 204.132.199.1 address, so that DNS lookups and reply packets get > handled correctly. I want all my inbound mail to get sent to the .1 > address too, but that's a simple MX record which works fine. Inbound, > everything is peachy. Outbound, everything seems normal too, EXCEPT..... > > ...all the outbound packets are MASQed as coming from the "real" external ip > address (.100) instead of the alias that I want them to be MASQed as (.1) > > Apparently this problem requires the iproute2 solution, in order to do > source address routing. I've asked Juanjo for confirmation, but haven't > received a reply yet. I just don't like the idea of replacing my routing > framework with an undocumented and semi-mysterious RPM from Russia.... If > nobody in the MASQ, IPCHAINS, or IPMASQADM community is willing to discuss > solutions that involve iproute2, then I don't think I want to stick my > little fingers into it either! :>) The big disclaimer in the latest ipmasq > howto seems to point to iproute2 to solve this sort of problem, but then > says it won't work with MASQed addresses, and then says none of the gurus > will answer questions about it. > > What I'm trying to reproduce is the same sort of IP address translation that > is present in a Cisco PIX firewall, which uses the concept of a "conduit" > between an internal host and an external host. You assign an external > address from your Internet address space to an internal host, and then set > up the address/ports/protocols of an Internet host that you want to > communicate with. All outbound traffic appears to come from the assigned > external address, so that replies are sent to the right firewall address. > Port Forwarding on the "conduit" allows incoming packets of the particular > specified combination into that internal host. > > Call me paranoid, but I have a number of services that I want to provide to > external (internet-based) clients and partners, and I want each > service/company to use a particular IP address instead of just globbing all > the services into a single IP address. I DONT want to use multiple > ethernet cards, because 8 addresses is just the beginning, and I'll run out > of port density quickly. I DONT want to use multiple firewalls, because > that's just harder to manage and inefficient. > > Does that clear up my context and intentions? Am I missing something > obvious? It seems like a lot of people want to accomplish this same sort > of thing.... I have to believe that Linux can do this, and it does seem to > be a routing issue as opposed to a MASQ or IPCHAINS issue. > > Doug > > -----Original Message----- > From: Gregory Leblanc [mailto:[EMAIL PROTECTED]] > Sent: Thursday, December 09, 1999 2:47 PM > To: [EMAIL PROTECTED] > Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED] > Subject: Re: [Masq] binding particular IP addr to masq'd packets -- me > too. > > [EMAIL PROTECTED] wrote: > > > > Any ideas guys? > > I meant to reply to this one if nobody else did, but I forgot, so I'll > post some comments below. Briefly, I think that this is a config > problem. > > > > > INTERNET ------- Router A > > | > > 192.168.0.0/30 > > | > > Linux masq/router > > | | | > > | | | > > 172.16.0.0/12 | | > > | | > > 216.174.15.192/26 | > > | > > 216.174.14.192/26 > > > > Here's my problem. I've got two public IP subnets that need to be routed > > through the Linux masq/router to Router A and router A handles everything > > from there. Also, Router A routes packets from the 172.16.0.0/12 subnet > > to about 5 other subnets, one of which is a private subnet. That's all > > fine and dandy. The only problem is that, when the Linux box masquerades > > packets that are destined for someplace outside of my IP space, it will > > translate all IP addresses to 192.168.0.2, which is the address of the > > ethernet card which connects to Router A. Router A receives these packets > > on 192.168.0.1 and deals with them then. > > So your masq/router has 4 interfaces, 172.16.0.0 MASK 255.240.0.0, > 216.174.15.192 MASK 255.255.255.192, 216.174.14.192 MASK > 255.255.255.192, and 192.168.0.0 MASK 255.255.255.252. (I had to > translate those to something that I understand, I don't think binary > anymore) The problem that you're having is that packets destined for an > internet IP address, go through the 192.168.x.x interface, and get > 192.168.0.2 address as the source. What is supposed to be MASQ'ed > here? Seems to me that you should turn off masq for those machines, and > just have the machine route those packets to the net, unless I'm missing > something. Can you provide some more information on goals here? > > > > > Obviously, nothing can be routed on the Internet with an IP from the > > 192.168.0.0/16 network, so this isn't going to work. Does anyone know how > > to make the Linux masq/router translate packet IP addrs to a particular > > address, and THEN route them? > > Sure, you have it route them out an interface with that address, that's > how masq works. The MASQ machine holds that IP address, and clients > behind it seem to all be that machine to the outside world. > > _______________________________________________ > Masq maillist - [EMAIL PROTECTED] > Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES >UNSUBSCRIBING! > or email to [EMAIL PROTECTED] > > PLEASE read the HOWTO and search the archives before posting. > You can start your search at http://www.indyramp.com/masq/ > Please keep general linux/unix/pc/internet questions off the list. _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
