/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'm going to verify my understand of what's below, tell me if I've totally blown it. > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] > Sent: Friday, December 10, 1999 6:55 PM > To: [EMAIL PROTECTED]; [EMAIL PROTECTED] > Subject: [Masq] RE: binding particular IP addr to masq'd > packets -- more > details > > /* HINT: Search archives @ http://www.indyramp.com/masq/ > before posting! */ > > Greg, it's 99% there, but that last 1% is the killer. Isn't it always... > > From the actual firewall box, if I telnet to machine A, the > packets come > from the IP address of my correctly aliased and routed port. > So I think > everything is just jiffy.... > > BUT -- and this is the killer -- > > when I telnet from any of the internal hosts, to the same > destination address, the packets come from the IP address of the > "real" external interface -- because they are getting Masqueraded. > The route doesn't seem to come into play at all, which is really > puzzling. > > > Here is my sanitized routing table, along with the relevant > bits from my > ipchains, ipmasqadm, and routing commands, plus the relevant > networking info > for context > These three are on the router... > eth0=172.16.1.1 (internal), 24 bit mask > eth1=192.168.1.1 (external), 24 bit mask > gateway=192.168.1.254 > This one is an internal host... > internal host=172.16.1.232 This one is on the router? > eth1:232=192.168.1.232 (external alias) > Some other box... > destination host=210.210.210.210 > > Routing table: > Destination Gateway Mask Device > 0.0.0.0 192.168.1.254 0.0.0.0 eth1 > 172.16.1.0 0.0.0.0 255.255.255.0 eth0 > 192.168.1.0 0.0.0.0 255.255.255.0 eth1 > 192.168.1.232 0.0.0.0 255.255.255.255 eth1 (should list > eth1:232) > 210.210.210.210 192.168.1.254 255.255.255.255 eth1 > (should list > eth1:232) > > Notice that the output of netstat -rn doesn't show the alias > devices, just > the real device... Makes it hard to decipher, in case anybody > out there is > working on the source for those utilities... > Here's how that routing table came to be... > > ifconfig eth1:232 192.168.1.232 up > > route add -host 192.168.1.232 dev eth1:232 > route add -host 210.210.210.210 gw 192.168.1.254 dev eth1:232 > > ipchains -A lan-inet -p tcp -s 172.16.1.232 25 -d > 210.210.210.210 -j MASQ > ******* Add a rule to the lan-inet chain, for packets matching these specs: protocol TCP source address of the internal machine (on port 25??, can you do that, don't have a man page handy) destination of the external host All such packets should be MASQ'd I don't understand what you're trying to with this rule. > ipchains -A lan-inet -p tcp -s 172.16.1.232 -d > 210.210.210.210 --dport 25 -j > MASQ ******* Add a rule to the lan-inet chain for packets matching these specs: protocol TCP source address of the external box (on port 25??, again) destination of the internal host. All such packets should be MASQ'd I'm reading this one as "take all packets from the internal host that are going to the external host's port 25, and MASQ them." Is this correct? > ipchains -A inet-lan -p tcp -s 210.210.210.210 25 -d > 192.168.1.232 -j ACCEPT Add a rule to the inet-lan (as opposed to the lan-inet, right? This would be for things FROM the LAN, to the iNET) matching these specs: protocol TCP source address of external box destination of an alias on the router, with destination port of 25 accept all such packets This one doesn't make sense to me either. > ipchains -A inet-lan -p tcp -s 210.210.210.210 -d > 192.168.1.232 --dport 25 > -j MASQ Add a rule to the inet-lan chain for packets matching these specs: Protocol TCP source address of the external host destination address of alias on the router, with destination port of 25 Masq all such packets. I'm reading this as "Take all packets from the external machine that are destined for the alias of the router, on port 25, and masq them" > > ipmasqadm portfw -p tcp -L 192.168.1.232 25 -R 172.16.1.232 25 Forward all TCP requests coming in on port 25 of our alias on the router, to port 25 on the internal machine. So you're wanting that address to seem to answer requests on port 25, that seems easy. > using this configuration, if I telnet from the masqing box, to > 210.210.210.210 on port 25, I connect just fine. Packet traces > using tcpdump show the connection is coming from ip address Which machine are you running these on? If at all possible, TCPDUMP should be run on another machine plugged into the hub with the external nic, and the hub with the internal nic. (or something equivalent. a switch will NOT work here, unless you can tell it to send all data to a specific port in addition to the destination) > 192.168.1.232, as it > should be. All is good. Incoming packets from the > 210.210.210.210 host > arrive just fine at the internal mail server. Pings, > traceroutes and nmaps > to the 210.210.210.210 host all originate from the alias address of > 192.168.1.232. Routing obviously works. YAY! We love it when things work... > > So, in order to test the outgoing connection I use this same > configuration. > If I telnet from the 172.16.1.232 host to 210.210.210.210 on > port 25, I > connect just fine. **BUT** packet traces show the > connection is coming > from ip address 192.168.1.1, which is WRONG for what I'm trying to > do. > > The problem seems to be that when I specify that the outbound > connections > (the ones marked ****** above) should be MASQed, the packets > get written > with the default ip address of the "forwarding" interface, > which is the .1 > address -- it's as if the MASQ code doesn't give a damn that a > virtual device is specified as the device to use for that route. > > Do you see my problem more clearly now? Is there a way that > I can specify > WHICH DEVICE I want the packets to be forwarded with and be MASQed > as? Methinks so, but I need Fuzzy Fox or somebody to read over those ipchains rules (or I need to go read the man page yet again) to make sure that they're right. BTW, doesn't linux do a 'route -e' or something to print the routing table with route? That might give a clearer picture of the table, but I'm not sure. If you explain the rules that I didn't understand above, (I'll go look them up as well) I may be able to figure the rest of it out. Later, Greg > > > -----Original Message----- > > From: Gregory Leblanc [mailto:[EMAIL PROTECTED]] > > Sent: Friday, December 10, 1999 4:30 PM > > To: '[EMAIL PROTECTED]'; [EMAIL PROTECTED] > > Subject: RE: binding particular IP addr to masq'd packets -- more > > details > > > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > How about a look at that routing table? :) I see what you want > > to do, and it should be simple to do with the built in routing > > and masq features for linux, without some other routing stuff. > > Hard to say why it's not working the way that you expect. Greg > > > > [everything snipped] > > > > -----BEGIN PGP SIGNATURE----- > > Version: PGPfreeware 6.5.1 for non-commercial use <http://www.pgp.com> > > iQA/AwUBOFGM9ZLW/u8jW+lnEQKhhQCglG/90X/VgARJ+vKRDEa+YsAPLtQAoIoG > EYxuh3Yt5q0QqKG2VQ45Y1aK > =FlEE > -----END PGP SIGNATURE----- _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ - -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list. -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.1 for non-commercial use <http://www.pgp.com> iQA/AwUBOFLyQpLW/u8jW+lnEQIMmQCgtDfxBLpnEwlPTgv6UxAqQBqAO2EAoPVN PjcSsg2EwL/ULR6mjO3LDhay =auYA -----END PGP SIGNATURE----- _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
