/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
I see. Sorry for asking a question that is already in the HOWTO. I must
have missed it when reading the HOWTO the first time. Guess I'll have to
get another NIC if I want to do this...
Thanks again!
Craig
On Sat, 22 Jan 2000, Shahid Sheikh wrote:
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
> Ahh! Sorry for misleading you earlier. This cannot be done. Have a look at
> this http://members.home.net/ipmasq/ipmasq-HOWTO-1.80-7.html#ss7.23
>
> Shahid
>
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> Of Craig Baird
> Sent: Saturday, January 22, 2000 2:03 PM
> To: Shahid Sheikh
> Cc: [EMAIL PROTECTED]
> Subject: RE: [Masq] masq'ing to different external addresses
>
>
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
> I think so. As a test, here's what I set up:
>
> On eth0 (my external IP), I have the address 192.168.0.5.
> On eth0:1 (the aliased IP), I have the address 192.168.0.33
>
> I have two other NICs in the machine to run masq'ed networks:
>
> eth1 has the address 10.0.7.1
> eth2 has the address 10.0.8.1
>
> I have 10.0.7.0 network set up to masqerade as 192.168.0.5 (eth0). This
> seems to be working fine.
>
> I want 10.0.8.0 to masqerade as 192.168.0.33, the virtual IP on eth0:1.
>
> I can't seem to get it to masqerade to the virutal IP. With the way I
> have it set up, I get "destination net unreachable" when I try to ping
> anything outside the internal network.
>
> Here's what I have in rc.firewall in regard to the virutal IP (note that I
> am using kernel 2.0.36 and ipfwadm):
>
> /sbin/ipfwadm -I -a accept -V 10.0.8.1 -S 10.0.8.0/24 -D 0.0.0.0/0
>
> /sbin/ipfwadm -I -a accept -V 192.168.0.33 -S 0.0.0.0/0 -D 192.168.0.33/24
>
> /sbin/ipfwadm -O -a accept -V 10.0.8.1 -S 0.0.0.0/0 -D 10.0.8.0/24
>
> /sbin/ipfwadm -O -a accept -V 192.168.0.33 -S 192.168.0.33/32 -D 0.0.0.0/0
>
> /sbin/ipfwadm -F -a masquerade -V 192.168.0.33 -S 10.0.8.0/24 -D 0.0.0.0/0
>
> I don't think it's a problem with the rules because I'm not getting
> anything logged.
>
> Thanks for any help that you can provide.
>
> Craig
>
>
>
> On Sat, 22 Jan 2000, Shahid Sheikh wrote:
>
> > >From what little I understand about how the IP aliasing and IPCHAINS
> works,
> > I dont see any reason why it wouldn't work. Never tried it myself though.
> > Are you sure that you have an ipchains input rule to not reject any
> packets
> > coming to the aliased IP?
> >
> > Shahid
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> > Of Craig Baird
> > Sent: Thursday, January 20, 2000 8:04 PM
> > To: [EMAIL PROTECTED]
> > Subject: [Masq] masq'ing to different external addresses
> >
> >
> > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting!
> */
> >
> >
> > I have a situation where I have a masq'ed network, and the customer needs
> > one of his machines to appear to the outside world with a different IP
> > than the rest of his network. The reason for this is that he connects
> > from this machine via telnet to a machine on the Internet that requires
> > him to have a static IP. They could set it up to give access to our
> > external IP address, but then that would give his entire network access,
> > which he doesn't want. He needs just that one machine to appear on the
> > Internet with a different IP address. Is there an easy way to accomplish
> > this?
> >
> > I thought about the possibility of using a virtual IP address bound
> > to the same ethernet card as my external IP, and using ipfwadm to
> > masquerade his internal address as the virtual IP. I tried it, and
> > couldn't seem to make it work. Has anyone done anything like this before?
> >
> > Craig
> >
> > _______________________________________________
> > Masq maillist - [EMAIL PROTECTED]
> > Admin requests can be handled at http://www.indyramp.com/masq-list/ --
> THIS
> > INCLUDES UNSUBSCRIBING!
> > or email to [EMAIL PROTECTED]
> >
> > PLEASE read the HOWTO and search the archives before posting.
> > You can start your search at http://www.indyramp.com/masq/
> > Please keep general linux/unix/pc/internet questions off the list.
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
> INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
>UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.