/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hi all! I have seen some discussion in the list archives towards this topic,
but nothing related to the peculiar results I am seeing.
I've recently installed a Linux firewall using masquerade to provide internet
access for/to a bunch of machines. One happens to be an NT server running HTTP,
SMTP, etc... Another is a Linux box running an SSH server...I use aliases and
FW marking to redirect traffic destined for a particular "live" IP to the
internal servers, e.g.:
(firewall eth0 = xxx.xxx.xxx.3, eth0:0 = xxx.xxx.xxx.4, eth1 = yyy.yyy.yyy.2)
ipchains -A input -p tcp -m 1 --sport 1024: -d xxx.xxx.xxx.3 http -j ACCEPT
ipchains -A input -p tcp -m 2 --sport 1024: -d xxx.xxx.xxx.4 ssh -j ACCEPT
ipmasqadm mfw -I -m 1 -r yyy.yyy.yyy.3
ipmasqadm mfw -I -m 2 -r yyy.yyy.yyy.4
where xxx.xxx.xxx are real IP's, yyy.yyy.yyy is private (192.168.0)
Everything works perfectly (except incoming passive FTP).
However.
I wanted traffic _FROM_ the linux server to go out (MASQ) on the secondary,
alias IP. After much research (there's seems not to be much out there on this
topic - although this list's archives have some threads, all appear unresolved),
I discovered the IProute2 package. More reading later, I find that the command:
"ip ru add yyy.yyy.yyy.4 nat xxx.xxx.xxx.4"
can be used to tell the system to MASQ/NAT the source IP out on the specified
target IP. Voila, it works!!!
But.
Paying close attention to my IPchains accounting shows that the outbound traffic
going from yyy.yyy.yyy.4 _ISN'T EVEN HITTING THE FORWARD CHAIN_. _Everything_
from the Linux box is masq'ed, not just the specific services I indicated (via
fascist masqing), and the packet/byte counters from ipchains -L -v -n do not
show corresponding activity.
What am I missing? I'm still trying to figure out where the ip tool comes into
play here with respect to ipchains, it must nat the source _before_ routing, but
then the traffic shouldn't be allowed through my forward chain. Any
criticism/advice/info is very much appreciated, I feel like I'm so close to
having a solid understanding of this stuff!!!
Thanks!
Dardo D Kleiner
Software Product Engineer
CIPS, Corp.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.