/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I think so.  As a test, here's what I set up:

On eth0 (my external IP), I have the address 192.168.0.5.
On eth0:1 (the aliased IP), I have the address 192.168.0.33

I have two other NICs in the machine to run masq'ed networks:

eth1 has the address 10.0.7.1
eth2 has the address 10.0.8.1

I have 10.0.7.0 network set up to masqerade as 192.168.0.5 (eth0). This
seems to be working fine.

I want 10.0.8.0 to masqerade as 192.168.0.33, the virtual IP on eth0:1.

I can't seem to get it to masqerade to the virutal IP.  With the way I
have it set up, I get "destination net unreachable" when I try to ping
anything outside the internal network.

Here's what I have in rc.firewall in regard to the virutal IP (note that I
am using kernel 2.0.36 and ipfwadm):

/sbin/ipfwadm -I -a accept -V 10.0.8.1 -S 10.0.8.0/24 -D 0.0.0.0/0

/sbin/ipfwadm -I -a accept -V 192.168.0.33 -S 0.0.0.0/0 -D 192.168.0.33/24

/sbin/ipfwadm -O -a accept -V 10.0.8.1 -S 0.0.0.0/0 -D 10.0.8.0/24

/sbin/ipfwadm -O -a accept -V 192.168.0.33 -S 192.168.0.33/32 -D 0.0.0.0/0

/sbin/ipfwadm -F -a masquerade -V 192.168.0.33 -S 10.0.8.0/24 -D 0.0.0.0/0

I don't think it's a problem with the rules because I'm not getting
anything logged.

Thanks for any help that you can provide.

Craig



On Sat, 22 Jan 2000, Shahid Sheikh wrote:

> >From what little I understand about how the IP aliasing and IPCHAINS works,
> I dont see any reason why it wouldn't work. Never tried it myself though.
> Are you sure that you have an ipchains input rule to not reject any packets
> coming to the aliased IP?
> 
> Shahid
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> Of Craig Baird
> Sent: Thursday, January 20, 2000 8:04 PM
> To: [EMAIL PROTECTED]
> Subject: [Masq] masq'ing to different external addresses
> 
> 
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> 
> 
> I have a situation where I have a masq'ed network, and the customer needs
> one of his machines to appear to the outside world with a different IP
> than the rest of his network.  The reason for this is that he connects
> from this machine via telnet to a machine on the Internet that requires
> him to have a static IP.  They could set it up to give access to our
> external IP address, but then that would give his entire network access,
> which he doesn't want.  He needs just that one machine to appear on the
> Internet with a different IP address.  Is there an easy way to accomplish
> this?
> 
> I thought about the possibility of using a virtual IP address bound
> to the same ethernet card as my external IP, and using ipfwadm to
> masquerade his internal address as the virtual IP.  I tried it, and
> couldn't seem to make it work.  Has anyone done anything like this before?
> 
> Craig
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
> INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to