/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
[EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote:
>
> Is it possible to forward UN-masqueraded to external ? Do you know how?
It certainly is possible, but the question is, will it be useful?
For instance, if your private LAN uses IP addresses that are publicly
routeable, that is, some router on the external LAN knows how to route
traffic back to your masq box when trying to reach that private LAN...
then certainly, you can send out the un-masq'd traffic. You would
simply use a forwarding target of ACCEPT instead of MASQ in your forward
chain.
However, if you are using private IP addresses (10.*, or 192.168.*,
etc), then forwarding un-masq'd traffic will not be useful to you!
Sure, the packets can go out, and reach their targets, but the target
host will be unable to reply back. That is why the traffic must be
masqueraded; the masq box presumably has a reply-able IP address, and
the clients are making use of that.
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience.
sometimes known as David DeSimone || Experience comes from bad judgment."
http://www.dallas.net/~fox/ || -- Life Lessons
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.