/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Here is a thought, though I have not had the opportunity to test it, that may help 
your situation.  If
you test this please post your results, I would be very interested.  I can't test it 
at home because I
only have 1 IP.  I am going to be setting up a firewall at work soon in a situation 
similar to yours,
so I am interested if this will work.  As I understand it, it should.

Couldn't you specify a source and a destination address in your IPCHAINS rules?

Something like:

First setup your IP alies on eth1.

Then in your rc.firewall rules (or where ever you are putting them):


     #incoming rules
     ipchains -F input
     ipchains -P input REJECT
     #I am assuming eth0 is your nic for your internal 10.1.x network
     ipchians -A input -i eth0 -s 10.1.1.0/24 -d 0.0.0.0/0 -j ACCEPT
     #no spoofing
     ipchains -A input -i eth1 -s 10.1.1.0/24 -d 0.0.0.0/0 -j REJECT

     ipchains -A input -i eth1 -s 10.1.1.1/24 -d 204.132.199.1/24 -j ACCEPT
     ipchains -A input -i eth1 -s 10.1.1.2/24 -d 204.132.199.2/24 -j ACCEPT
     ipchains -A input -i eth1 -s 10.1.1.3/24 -d 204.132.199.3/24 -j ACCEPT
     ipchains -A input -i eth1 -s 10.1.1.4/24 -d 204.132.199.4/24 -j ACCEPT

     ipchains -A input -i lo -s 0/0 -d 0/0 -j ACCEPT

     ipchains -A input -s 0/0 -d 0/0 -l -j REJECT

     #Outgoing
     ipchains -F output
     ipchains -P output REJECT

     ipchains -A output -i eth0 -s 0/0 -d 10.1.1.0/24 -j ACCEPT
     ipchains -A output -i eth1 -s 0/0 -d 10.1.1.0/24 -l -j REJECT
     ipchains -A output -i eth1 -s 10.1.1.0/24 -d 0/0 -l -j REJECT
     ipchains -A output -i eth1:1 -s 204.132.199.1/24 -d 0/0 -j ACCEPT
     ipchains -A output -i eth1:2 -s 204.132.199.2/24 -d 0/0 -j ACCEPT
     ipchains -A output -i eth1:3 -s 204.132.199.3/24 -d 0/0 -j ACCEPT
     ipchains -A output -i eth1 -s 204.132.199.4/24 -d 0/0 -j ACCEPT

     ipchains -A output -i lo -s 0/0 -d 0/0 -j ACCEPT

     ipchains -A output -s 0/0 -d 0/0 -l -j REJECT

     #Forwarding
     #flush portfw
     ipmasqadm portfw -f
     #forward mail addresses
     ipmasqadm portfw -a -P tcp -L 204.132.199.1 25 -R 10.1.1.1 25
     ipmasqadm portfw -a -P tcp -L 204.132.199.1 110 -R 10.1.1.1 110
     #forward WWW
     ipmasqadm portfw -a -P tcp -L 204.132.199.2 80 -R 10.1.1.2 80
     #forward LDAP
     ipmasqadm portfw -a -P tcp -L 204.132.199.3 389 -R 10.1.1.3 389

     #handle the forwarding and MASQing of above services
     ipchains -A forward -s 10.1.1.1/24 -i eth1:1 -d 204.132.199.1/24 -j MASQ
     ipchains -A forward -s 10.1.1.2/24 -i eth1:2 -d 204.132.199.2/24 -j MASQ
     ipchains -A forward -s 10.1.1.3/24 -i eth1:3 -d 204.132.199.3/24 -j MASQ

     #handle forwarding and MASQing for others. I think this will forward everything 
else that
     doesn't match the above.
     ipchains -A forward -s 10.1.1.0/24 -i eth1 -d 204.132.199.4/24 -j MASQ

     #reject everything else
     ipchains -A forward -s 0/0 -d 0/0 0. -j REJECT

I'm sure you will want to add to add other things to it, but I think this would be the 
bulk of it.
Let me know if this works for you I would be very interested.

--
Daniell Freed
Computer Services
Dewitt, Ross, & Stevens

He who fights with monsters might take care
lest he thereby become a monster.
And if you gaze for long into an abyss,
the abyss gazes also into you.

Beyond Good and Evil
Friedrich Wilhelm Nietzche


[EMAIL PROTECTED] wrote:

> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
> My particular situation is a bit different.  In my little world, my
> firewall/router is dual-homed.  Assume the external IP address (eth1) is
> 204.132.199.100.  However, I had a number of aliases (eth1:1-eth1:8) that
> are aliases of the external address.   For simplicity, jut assume that I
> have them set as 204.132.199.1-8, using a simple 24-bit class-c mask.   Each
> alias is port forwarding a particular service to an internal host via
> ipmasqadm portfw.
>
> For instance, lets say that I have an internal host 10.1.1.1 that is a mail
> server.   The objective is that outbound mail should LOOK like it's coming
> from the 204.132.199.1 address, so that DNS lookups and reply packets get
> handled correctly.   I want all my inbound mail to get sent to the .1
> address too, but that's a simple MX record which works fine.   Inbound,
> everything is peachy.   Outbound, everything seems normal too, EXCEPT.....
>
> ...all the outbound packets are MASQed as coming from the "real" external ip
> address (.100) instead of the alias that I want them to be MASQed as (.1)
>
> Apparently this problem requires the iproute2 solution, in order to do
> source address routing.   I've asked Juanjo for confirmation, but haven't
> received a reply yet.   I just don't like the idea of replacing my routing
> framework with an undocumented and semi-mysterious RPM from Russia....  If
> nobody in the MASQ, IPCHAINS, or IPMASQADM community is willing to discuss
> solutions that involve iproute2, then I don't think I want to stick my
> little fingers into it either! :>)   The big disclaimer in the latest ipmasq
> howto seems to point to iproute2 to solve this sort of problem, but then
> says it won't work with MASQed addresses, and then says none of the gurus
> will answer questions about it.
>
> What I'm trying to reproduce is the same sort of IP address translation that
> is present in a Cisco PIX firewall, which uses the concept of a "conduit"
> between an internal host and an external host.   You assign an external
> address from your Internet address space to an internal host, and then set
> up the address/ports/protocols of an Internet host that you want to
> communicate with.   All outbound traffic appears to come from the assigned
> external address, so that replies are sent to the right firewall address.
> Port Forwarding on the "conduit" allows incoming packets of the particular
> specified combination into that internal host.
>
> Call me paranoid, but I have a number of services that I want to provide to
> external (internet-based) clients and partners, and I want each
> service/company to use a particular IP address instead of just globbing all
> the services into a single IP address.   I DONT want to use multiple
> ethernet cards, because 8 addresses is just the beginning, and I'll run out
> of port density quickly.   I DONT want to use multiple firewalls, because
> that's just harder to manage and inefficient.
>
> Does that clear up my context and intentions?   Am I missing something
> obvious?   It seems like a lot of people want to accomplish this same sort
> of thing....  I have to believe that Linux can do this, and it does seem to
> be a routing issue as opposed to a MASQ or IPCHAINS issue.
>
> Doug
>
> -----Original Message-----
> From: Gregory Leblanc [mailto:[EMAIL PROTECTED]]
> Sent: Thursday, December 09, 1999 2:47 PM
> To: [EMAIL PROTECTED]
> Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]
> Subject: Re: [Masq] binding particular IP addr to masq'd packets -- me
> too.
>
> [EMAIL PROTECTED] wrote:
> >
> > Any ideas guys?
>
> I meant to reply to this one if nobody else did, but I forgot, so I'll
> post some comments below.  Briefly, I think that this is a config
> problem.
>
> >
> > INTERNET ------- Router A
> >                    |
> >              192.168.0.0/30
> >                    |
> >            Linux masq/router
> >             |     |      |
> >             |     |      |
> >     172.16.0.0/12 |      |
> >                   |      |
> >       216.174.15.192/26  |
> >                          |
> >                 216.174.14.192/26
> >
> > Here's my problem.  I've got two public IP subnets that need to be routed
> > through the Linux masq/router to Router A and router A handles everything
> > from there.  Also, Router A routes packets from the 172.16.0.0/12 subnet
> > to about 5 other subnets, one of which is a private subnet.  That's all
> > fine and dandy.  The only problem is that, when the Linux box masquerades
> > packets that are destined for someplace outside of my IP space, it will
> > translate all IP addresses to 192.168.0.2, which is the address of the
> > ethernet card which connects to Router A.  Router A receives these packets
> > on 192.168.0.1 and deals with them then.
>
> So your masq/router has 4 interfaces, 172.16.0.0 MASK 255.240.0.0,
> 216.174.15.192 MASK 255.255.255.192, 216.174.14.192 MASK
> 255.255.255.192, and 192.168.0.0 MASK 255.255.255.252.  (I had to
> translate those to something that I understand, I don't think binary
> anymore)  The problem that you're having is that packets destined for an
> internet IP address, go through the 192.168.x.x interface, and get
> 192.168.0.2 address as the source.  What is supposed to be MASQ'ed
> here?  Seems to me that you should turn off masq for those machines, and
> just have the machine route those packets to the net, unless I'm missing
> something.  Can you provide some more information on goals here?
>
> >
> > Obviously, nothing can be routed on the Internet with an IP from the
> > 192.168.0.0/16 network, so this isn't going to work.  Does anyone know how
> > to make the Linux masq/router translate packet IP addrs to a particular
> > address, and THEN route them?
>
> Sure, you have it route them out an interface with that address, that's
> how masq works.  The MASQ machine holds that IP address, and clients
> behind it seem to all be that machine to the outside world.
>
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
>UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to