/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hello all ip-masqerading people!
Can anybody help me with the following problem:
First, the preamble. I am system administrator in a mid-size bank office and
I have such a network:
!----------!
LAN 10.8.6.0/24 ! Router ! PPP link CorpNet
--------------------------------------! 10.8.6.1 !----------- 10.0.0.0/8
! ! ! !----------!
! ! !
! ! !
10.8.6.32 ! !
10.8.6.33 !
!
...
I don't like two things in this network:
1) I want to shape the traffic routed from the various hosts on my LAN to
the PPP link but the router 10.8.6.1 is too dumb for this purpose. And
what's more - I cannot control this router, it is controlled remotely by the
guys from the corporative network.
2) The most of the hosts on the LAN cannot access the servers in corporate
network because of the firewall somewhere in the corpnet which filters them
out by source address. Just a few hosts on the LAN can pass the firewall
(including mine) - very unwise policy attempting to limit the traffic in
the corporate network. Many people (connected to LAN) really need to access
the servers in corporate net, but I cannot affect this policy in any way and
it's too troublesome to write the letters to corporate network bosses on
every occasion.
So I tried to use something like this:
!---------! !----------!
LAN 10.8.6.0/24 ! Masq ! ! Router ! PPP link CorpNet
-----------------------! eth0 !----! 10.8.6.1 !----------- 10.0.0.0/8
! ! ! ! 10.8.6.2! !----------!
! ! ! ! eth0:1 !
! ! ! ! 10.8.6.7!
10.8.6.32 ! ! !---------!
10.8.6.33 !
!
...
In this scheme address 10.8.6.2 (interface eth0) is used by masqerading host
(RedHat Linux 6.0, kernel 2.2.13) to reach the machines on LAN and
10.8.6.7 (eth0:1) is used to reach the corporate network. Both are assigned
to the same ethernet card; the first is not allowed to pass the corporate
firewall but the second is allowed. All the hosts on LAN use the Linux
machine address (10.8.6.2) as a default route and the Linux machine uses
10.8.6.1 as a route to corporate net. This is my
/etc/sysconfig/static-routes file:
eth0:1 net 10.0.0.0 netmask 255.0.0.0 gw 10.8.6.1
eth0 net 10.8.6.0 netmask 255.255.255.0
The Linux box masqerades all the forwarded packets (it also serves as a
gateway to Internet):
LOCALNET="10.8.6.0/24"
ipchains -A forward -s $LOCALNET -j MASQ
If al this worked I could control (at least partially) the bandwidth usage
in PPP link and the people from the LAN could walk in corporate network (if
I allow them). But all this doesn't work. And I beleive I understand why.
When I'm trying to ping some host in the corporate net from some host on the
LAN (which is not permitted to traverse the corporate firewall) immediately
after it came up, the first packet passes the firewall but all the
subsequent do not. I beleive that when Linux receives the first packet it
forwards it properly but it also answers to the pinging host (perhaps with
ICMP Redirect packet - I am not familar enough with IP protocol details)
that there is the shorter route to the corpnet - directly through 10.8.6.1.
And the subsequent ping packets use this shorter way and are filtered out
because they were not masqeraded.
So now I ask: can I do something to make the hosts on LAN use the Linux box
as a gateway (masqerading) to corporate net. Disabling all outgoing ICMP
Redirect packets seems to be too drastic measure (and I don't even know
would
it help and is it possible at all). I cannot change the IP address to all
the LAN host (to move them to another subnet) because many of them use the
"unmasqeradable" protocols (such as SMB). And I cannot move to another
subnet just some of them because all the hosts on the LAN must communicate
to
each other.
So can anybody advise me what to do?
Thanks.
________________________________
Dmitriy Stepanenko aka Mudropolk
e-mail: [EMAIL PROTECTED]
phone: (380)(06264)1-93-06, local 41-93-06
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.