/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Greg, it's 99% there, but that last 1% is the killer. >From the actual firewall box, if I telnet to machine A, the packets come from the IP address of my correctly aliased and routed port. So I think everything is just jiffy.... BUT -- and this is the killer -- when I telnet from any of the internal hosts, to the same destination address, the packets come from the IP address of the "real" external interface -- because they are getting Masqueraded. The route doesn't seem to come into play at all, which is really puzzling. Here is my sanitized routing table, along with the relevant bits from my ipchains, ipmasqadm, and routing commands, plus the relevant networking info for context eth0=172.16.1.1 (internal), 24 bit mask eth1=192.168.1.1 (external), 24 bit mask gateway=192.168.1.254 internal host=172.16.1.232 eth1:232=192.168.1.232 (external alias) destination host=210.210.210.210 Routing table: Destination Gateway Mask Device 0.0.0.0 192.168.1.254 0.0.0.0 eth1 172.16.1.0 0.0.0.0 255.255.255.0 eth0 192.168.1.0 0.0.0.0 255.255.255.0 eth1 192.168.1.232 0.0.0.0 255.255.255.255 eth1 (should list eth1:232) 210.210.210.210 192.168.1.254 255.255.255.255 eth1 (should list eth1:232) Notice that the output of netstat -rn doesn't show the alias devices, just the real device... Makes it hard to decipher, in case anybody out there is working on the source for those utilities... Here's how that routing table came to be... ifconfig eth1:232 192.168.1.232 up route add -host 192.168.1.232 dev eth1:232 route add -host 210.210.210.210 gw 192.168.1.254 dev eth1:232 ipchains -A lan-inet -p tcp -s 172.16.1.232 25 -d 210.210.210.210 -j MASQ ******* ipchains -A lan-inet -p tcp -s 172.16.1.232 -d 210.210.210.210 --dport 25 -j MASQ ******* ipchains -A inet-lan -p tcp -s 210.210.210.210 25 -d 192.168.1.232 -j ACCEPT ipchains -A inet-lan -p tcp -s 210.210.210.210 -d 192.168.1.232 --dport 25 -j MASQ ipmasqadm portfw -p tcp -L 192.168.1.232 25 -R 172.16.1.232 25 using this configuration, if I telnet from the masqing box, to 210.210.210.210 on port 25, I connect just fine. Packet traces using tcpdump show the connection is coming from ip address 192.168.1.232, as it should be. All is good. Incoming packets from the 210.210.210.210 host arrive just fine at the internal mail server. Pings, traceroutes and nmaps to the 210.210.210.210 host all originate from the alias address of 192.168.1.232. Routing obviously works. So, in order to test the outgoing connection I use this same configuration. If I telnet from the 172.16.1.232 host to 210.210.210.210 on port 25, I connect just fine. **BUT** packet traces show the connection is coming from ip address 192.168.1.1, which is WRONG for what I'm trying to do. The problem seems to be that when I specify that the outbound connections (the ones marked ****** above) should be MASQed, the packets get written with the default ip address of the "forwarding" interface, which is the .1 address -- it's as if the MASQ code doesn't give a damn that a virtual device is specified as the device to use for that route. Do you see my problem more clearly now? Is there a way that I can specify WHICH DEVICE I want the packets to be forwarded with and be MASQed as? Doug > -----Original Message----- > From: Gregory Leblanc [mailto:[EMAIL PROTECTED]] > Sent: Friday, December 10, 1999 4:30 PM > To: '[EMAIL PROTECTED]'; [EMAIL PROTECTED] > Subject: RE: binding particular IP addr to masq'd packets -- more > details > > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > How about a look at that routing table? :) I see what you want to > do, and it should be simple to do with the built in routing and masq > features for linux, without some other routing stuff. Hard to say > why it's not working the way that you expect. > Greg > > [everything snipped] > > -----BEGIN PGP SIGNATURE----- > Version: PGPfreeware 6.5.1 for non-commercial use <http://www.pgp.com> > > iQA/AwUBOFGM9ZLW/u8jW+lnEQKhhQCglG/90X/VgARJ+vKRDEa+YsAPLtQAoIoG > EYxuh3Yt5q0QqKG2VQ45Y1aK > =FlEE > -----END PGP SIGNATURE----- _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
