/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Greg, it's 99% there, but that last 1% is the killer.

>From the actual firewall box, if I telnet to machine A, the packets come
from the IP address of my correctly aliased and routed port.   So I think
everything is just jiffy....

BUT -- and this is the killer --

when I telnet from any of the internal hosts, to the same destination
address, the packets come from the IP address of the "real" external
interface -- because they are getting Masqueraded.   The route doesn't seem
to come into play at all, which is really puzzling.


Here is my sanitized routing table, along with the relevant bits from my
ipchains, ipmasqadm, and routing commands, plus the relevant networking info
for context

eth0=172.16.1.1 (internal), 24 bit mask
eth1=192.168.1.1 (external), 24 bit mask
gateway=192.168.1.254

internal host=172.16.1.232
eth1:232=192.168.1.232 (external alias)

destination host=210.210.210.210

Routing table:
Destination             Gateway         Mask                    Device
0.0.0.0         192.168.1.254   0.0.0.0         eth1
172.16.1.0              0.0.0.0         255.255.255.0   eth0
192.168.1.0             0.0.0.0         255.255.255.0   eth1
192.168.1.232   0.0.0.0         255.255.255.255 eth1    (should list
eth1:232)
210.210.210.210 192.168.1.254   255.255.255.255 eth1    (should list
eth1:232)

Notice that the output of netstat -rn doesn't show the alias devices, just
the real device... Makes it hard to decipher, in case anybody out there is
working on the source for those utilities...
Here's how that routing table came to be...

ifconfig eth1:232 192.168.1.232 up

route add -host 192.168.1.232 dev eth1:232
route add -host 210.210.210.210 gw 192.168.1.254 dev eth1:232

ipchains -A lan-inet -p tcp -s 172.16.1.232 25 -d 210.210.210.210 -j MASQ
*******
ipchains -A lan-inet -p tcp -s 172.16.1.232 -d 210.210.210.210 --dport 25 -j
MASQ *******
ipchains -A inet-lan -p tcp -s 210.210.210.210 25 -d 192.168.1.232 -j ACCEPT
ipchains -A inet-lan -p tcp -s 210.210.210.210 -d 192.168.1.232 --dport 25
-j MASQ

ipmasqadm portfw -p tcp -L 192.168.1.232 25 -R 172.16.1.232 25


using this configuration, if I telnet from the masqing box, to
210.210.210.210 on port 25, I connect just fine.  Packet traces using
tcpdump show the connection is coming from ip address 192.168.1.232, as it
should be.   All is good.   Incoming packets from the 210.210.210.210 host
arrive just fine at the internal mail server.   Pings, traceroutes and nmaps
to the 210.210.210.210 host all originate from the alias address of
192.168.1.232.   Routing obviously works.

So, in order to test the outgoing connection I use this same configuration.
If I telnet from the 172.16.1.232 host to 210.210.210.210 on port 25, I
connect just fine.   **BUT** packet traces show the connection is coming
from ip address 192.168.1.1, which is WRONG for what I'm trying to do.

The problem seems to be that when I specify that the outbound connections
(the ones marked ****** above) should be MASQed, the packets get written
with the default ip address of the "forwarding" interface, which is the .1
address -- it's as if the MASQ code doesn't give a damn that a virtual
device is specified as the device to use for that route.

Do you see my problem more clearly now?   Is there a way that I can specify
WHICH DEVICE I want the packets to be forwarded with and be MASQed as?

Doug 





> -----Original Message-----
> From: Gregory Leblanc [mailto:[EMAIL PROTECTED]]
> Sent: Friday, December 10, 1999 4:30 PM
> To: '[EMAIL PROTECTED]'; [EMAIL PROTECTED]
> Subject: RE: binding particular IP addr to masq'd packets -- more
> details
> 
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> How about a look at that routing table?  :)  I see what you want to
> do, and it should be simple to do with the built in routing and masq
> features for linux, without some other routing stuff.  Hard to say
> why it's not working the way that you expect.
>       Greg
> 
> [everything snipped]
> 
> -----BEGIN PGP SIGNATURE-----
> Version: PGPfreeware 6.5.1 for non-commercial use <http://www.pgp.com>
> 
> iQA/AwUBOFGM9ZLW/u8jW+lnEQKhhQCglG/90X/VgARJ+vKRDEa+YsAPLtQAoIoG
> EYxuh3Yt5q0QqKG2VQ45Y1aK
> =FlEE
> -----END PGP SIGNATURE-----

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to