/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Daniell Freed <[EMAIL PROTECTED]> wrote:
>
>   #handle the forwarding and MASQing of above services
>   ipchains -A forward -s 10.1.1.1/24 -i eth1:1 -d 204.132.199.1/24 -j MASQ
>   ipchains -A forward -s 10.1.1.2/24 -i eth1:2 -d 204.132.199.2/24 -j MASQ
>   ipchains -A forward -s 10.1.1.3/24 -i eth1:3 -d 204.132.199.3/24 -j MASQ

The problem with this sort of thinking is that it doesn't match the way
ipchains works.  Ipchains is a system that reacts to traffic that is in
the process of coming into, going out of, or passing through the
machine.  The only way that it can *change* decisions about the packets,
is to allow, deny, or masquerade.

The first rule here says "if a packet has a source IP of 10.1.1.1
[you probably meant /32, but anyway], and has a destination IP of
204.132.199.1, and is trying to forward via eth1:1, then masquerade it!"

That sounds fine on the surface, but this rule will never be triggered!
Why?  Because there will never be a packet that tries to forward through
the eth1:1 interface!  Why?  Because there is no route information that
points to that interface!  The only packets that will leave eth1:1 will
be those generated by a socket bound specifically to that interface, by
a local process on the Linux box.

Thus, you NEED some method that will CHANGE the routing rules on the
machine.  Instead of all traffic being routed through eth1, you need
a routing subsystem that can decide, "Oh, a packet just came in from
10.1.1.1, destined for the external Internet.  I need to route that
packet via eth1:1!"  Only THEN will your ipchains rule, searching for
traffic forwarding via eth1:1 be triggered, and only THEN will the
outgoing packet be masqueraded with eth1:1's IP address.

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)     || "Good judgment comes from experience.
sometimes known as David DeSimone  ||  Experience comes from bad judgment."
  http://www.dallas.net/~fox/      ||                 -- Life Lessons

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to