/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ My responses are in-line with the text.... Hope it doesn't sound rude, but this is just getting rather frustrating -- every reply I get (and I've had a few now) says "oh yeah, it's simple, it'll work just fine" If it worked like normal MASQing, I wouldn't be taking up space on the NG by asking the question over and over. :>) Doug > -----Original Message----- > From: Fuzzy Fox [mailto:[EMAIL PROTECTED]] > Sent: Friday, December 10, 1999 12:31 PM > To: [EMAIL PROTECTED] > Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]; [EMAIL PROTECTED] > Subject: Re: binding particular IP addr to masq'd packets -- more > details > > > [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > > > > ...all the outbound packets are MASQed as coming from the "real" > > external ip address (.100) instead of the alias that I want > them to be > > MASQed as (.1) > > The packets will be masq'd as coming from the interface that > the packets > were routed to. Where does your default route point? Does > it point to > the .100 interface? Then that's what IP will be chosen. > Because that's > where you routed the traffic to. It's as simple as that. Unfortunately, it doesn't seem as simple as that in real life... In my case I know the exact destination that the packets are being sent to for each of my "conduits". If I set up a route (using std routing, not iproute2) to that external IP address via the ip-aliased ip address (such as 204.132.199.1) or by specifiying the dev ethX:Y, instead of just using the default route that goes out the .100 address, the packets STILL come from .100. Packets NEVER seem to go out a "virtual" interface regardless if the routing table has an entry for that specific destination address via a virtual interface. Can anybody demonstrate differently? Can you sniff outbound packets that are "from" the ALIASED interface/ip, not from the "real" interface/ip, with any sort of regular routing? To me, this means that the built-in routing system either doesn't understand/use the aliases, or the aliases are occuring at a higher/later section of the networking code. Obviously that a gross oversimplification, but it seems to me that this problem should have a very simple solution, without resorting to iproute2. I suspect the former is the actual problem, by virtue of the output of netstat -rn, where only the "real" interface > > > Apparently this problem requires the iproute2 solution, in > order to do > > source address routing. > > That's right. If you route the data to a different interface, it will > be masq'd with that interface's IP address. See how simple that is? Then why does the HOWTO say it won't work with MASQed addresses? MASQ and aliased interfaces don't seem to behave together the same way that MASQ and "real" interfaces work together... > > > I just don't like the idea of replacing my routing framework with an > > undocumented and semi-mysterious RPM from Russia.... > > That's quite unerstandable, for any security-concious administrator, > which I would hope that everyone here is one. But surely there is > source code available that can be examined, yes? Yes, I could examine the source code, but I HIGHLY doubt that I could identify a security hole in routing table subsystem source code, especially if the comments are non-existent or not in English. I *can* read and write in Russian, but not at the proficiency required for technical material. In any event, would YOU or any other responsible network administrator want to put an unmaintained, undocumented, and unsupported (in the community) routing system in place of the existing one, on a production firewall? Gee, in that context it does sound rather worthless. :>) So am I the only one in the MASQ community that wants outbound packets to get stamped as coming from a aliased interface instaead of the "real" interface? I would have guessed that EVERYONE using MASQ as part of their firewall structure would want to do this..... Guess I'd be wrong, eh? > > The big disclaimer in the latest ipmasq howto seems to point to > > iproute2 to solve this sort of problem, but then says it won't work > > with MASQed addresses, and then says none of the gurus will answer > > questions about it. > > I guess I need to read the howto more often. But I know that I, > personally, can't answer questions about this subject, > because I am not > in a position to try it, and so, I have no knowledge, and can't really > get any experience with it. > > Maybe when my multi-IP DSL setup comes to fruition, I can try such > things and report back to the list. > > -- > [EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes > from experience. > sometimes known as David DeSimone || Experience comes from > bad judgment." > http://www.dallas.net/~fox/ || -- Life Lessons _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
