/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Daniell Freed <[EMAIL PROTECTED]> wrote: > > #handle the forwarding and MASQing of above services > ipchains -A forward -s 10.1.1.1/24 -i eth1:1 -d 204.132.199.1/24 -j MASQ > ipchains -A forward -s 10.1.1.2/24 -i eth1:2 -d 204.132.199.2/24 -j MASQ > ipchains -A forward -s 10.1.1.3/24 -i eth1:3 -d 204.132.199.3/24 -j MASQ The problem with this sort of thinking is that it doesn't match the way ipchains works. Ipchains is a system that reacts to traffic that is in the process of coming into, going out of, or passing through the machine. The only way that it can *change* decisions about the packets, is to allow, deny, or masquerade. The first rule here says "if a packet has a source IP of 10.1.1.1 [you probably meant /32, but anyway], and has a destination IP of 204.132.199.1, and is trying to forward via eth1:1, then masquerade it!" That sounds fine on the surface, but this rule will never be triggered! Why? Because there will never be a packet that tries to forward through the eth1:1 interface! Why? Because there is no route information that points to that interface! The only packets that will leave eth1:1 will be those generated by a socket bound specifically to that interface, by a local process on the Linux box. Thus, you NEED some method that will CHANGE the routing rules on the machine. Instead of all traffic being routed through eth1, you need a routing subsystem that can decide, "Oh, a packet just came in from 10.1.1.1, destined for the external Internet. I need to route that packet via eth1:1!" Only THEN will your ipchains rule, searching for traffic forwarding via eth1:1 be triggered, and only THEN will the outgoing packet be masqueraded with eth1:1's IP address. -- [EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience. sometimes known as David DeSimone || Experience comes from bad judgment." http://www.dallas.net/~fox/ || -- Life Lessons _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
