/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
I think so. As a test, here's what I set up:
On eth0 (my external IP), I have the address 192.168.0.5.
On eth0:1 (the aliased IP), I have the address 192.168.0.33
I have two other NICs in the machine to run masq'ed networks:
eth1 has the address 10.0.7.1
eth2 has the address 10.0.8.1
I have 10.0.7.0 network set up to masqerade as 192.168.0.5 (eth0). This
seems to be working fine.
I want 10.0.8.0 to masqerade as 192.168.0.33, the virtual IP on eth0:1.
I can't seem to get it to masqerade to the virutal IP. With the way I
have it set up, I get "destination net unreachable" when I try to ping
anything outside the internal network.
Here's what I have in rc.firewall in regard to the virutal IP (note that I
am using kernel 2.0.36 and ipfwadm):
/sbin/ipfwadm -I -a accept -V 10.0.8.1 -S 10.0.8.0/24 -D 0.0.0.0/0
/sbin/ipfwadm -I -a accept -V 192.168.0.33 -S 0.0.0.0/0 -D 192.168.0.33/24
/sbin/ipfwadm -O -a accept -V 10.0.8.1 -S 0.0.0.0/0 -D 10.0.8.0/24
/sbin/ipfwadm -O -a accept -V 192.168.0.33 -S 192.168.0.33/32 -D 0.0.0.0/0
/sbin/ipfwadm -F -a masquerade -V 192.168.0.33 -S 10.0.8.0/24 -D 0.0.0.0/0
I don't think it's a problem with the rules because I'm not getting
anything logged.
Thanks for any help that you can provide.
Craig
On Sat, 22 Jan 2000, Shahid Sheikh wrote:
> >From what little I understand about how the IP aliasing and IPCHAINS works,
> I dont see any reason why it wouldn't work. Never tried it myself though.
> Are you sure that you have an ipchains input rule to not reject any packets
> coming to the aliased IP?
>
> Shahid
>
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> Of Craig Baird
> Sent: Thursday, January 20, 2000 8:04 PM
> To: [EMAIL PROTECTED]
> Subject: [Masq] masq'ing to different external addresses
>
>
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
> I have a situation where I have a masq'ed network, and the customer needs
> one of his machines to appear to the outside world with a different IP
> than the rest of his network. The reason for this is that he connects
> from this machine via telnet to a machine on the Internet that requires
> him to have a static IP. They could set it up to give access to our
> external IP address, but then that would give his entire network access,
> which he doesn't want. He needs just that one machine to appear on the
> Internet with a different IP address. Is there an easy way to accomplish
> this?
>
> I thought about the possibility of using a virtual IP address bound
> to the same ethernet card as my external IP, and using ipfwadm to
> masquerade his internal address as the virtual IP. I tried it, and
> couldn't seem to make it work. Has anyone done anything like this before?
>
> Craig
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
> INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.