/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Thanks for clearing that up. I was really misunderstanding the -d parameter in ipchains. Once you have pointed this out, my suggestion makes very little sense. That aside, why would would it matter what IP the outgoing packets have on them? If someone on the internet wants to connect to a mail server that is masqed with the proper ports are forwarded, replies from that mail server are going to go through the firewall and be forwarded back to the user on the internet. What difference does it make if the IP is different? I was just curious. Dan Fuzzy Fox wrote: > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ > > Daniell Freed <[EMAIL PROTECTED]> wrote: > > > > #handle the forwarding and MASQing of above services > > ipchains -A forward -s 10.1.1.1/24 -i eth1:1 -d 204.132.199.1/24 -j MASQ > > ipchains -A forward -s 10.1.1.2/24 -i eth1:2 -d 204.132.199.2/24 -j MASQ > > ipchains -A forward -s 10.1.1.3/24 -i eth1:3 -d 204.132.199.3/24 -j MASQ > > The problem with this sort of thinking is that it doesn't match the way > ipchains works. Ipchains is a system that reacts to traffic that is in > the process of coming into, going out of, or passing through the > machine. The only way that it can *change* decisions about the packets, > is to allow, deny, or masquerade. > > The first rule here says "if a packet has a source IP of 10.1.1.1 > [you probably meant /32, but anyway], and has a destination IP of > 204.132.199.1, and is trying to forward via eth1:1, then masquerade it!" > > That sounds fine on the surface, but this rule will never be triggered! > Why? Because there will never be a packet that tries to forward through > the eth1:1 interface! Why? Because there is no route information that > points to that interface! The only packets that will leave eth1:1 will > be those generated by a socket bound specifically to that interface, by > a local process on the Linux box. > > Thus, you NEED some method that will CHANGE the routing rules on the > machine. Instead of all traffic being routed through eth1, you need > a routing subsystem that can decide, "Oh, a packet just came in from > 10.1.1.1, destined for the external Internet. I need to route that > packet via eth1:1!" Only THEN will your ipchains rule, searching for > traffic forwarding via eth1:1 be triggered, and only THEN will the > outgoing packet be masqueraded with eth1:1's IP address. > > -- > [EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience. > sometimes known as David DeSimone || Experience comes from bad judgment." > http://www.dallas.net/~fox/ || -- Life Lessons > > _______________________________________________ > Masq maillist - [EMAIL PROTECTED] > Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES >UNSUBSCRIBING! > or email to [EMAIL PROTECTED] > > PLEASE read the HOWTO and search the archives before posting. > You can start your search at http://www.indyramp.com/masq/ > Please keep general linux/unix/pc/internet questions off the list. -- Daniell Freed Computer Services Dewitt, Ross, & Stevens He who fights with monsters might take care lest he thereby become a monster. And if you gaze for long into an abyss, the abyss gazes also into you. Beyond Good and Evil Friedrich Wilhelm Nietzche _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
