/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


My question is similar to the thread on masqing real IP addresses, but 
with a bit of a twist.

We recently got cable modem at home with a single assigned IP address.  We 
are seriously considering setting up a Linux firewall system with our 
various home machines behind it.  The firewall would be a normal 
configuration with two NICs, one connected to the cable modem and one to 
the internal network.

One of the machines that we are going to have on the local network needs 
to be able to establish a Kerberos5 connection with a remote machine.  
Kerberos packs the IP address of the sending machine into the messsage 
body in addition to the IP address in the message header.  These have to 
match for the receiving machine to accept the message.  Thus, we can't 
give the local machine a private IP address because the IPmasqed address 
in the message header will be that of the firewall machine and will be 
different from the private address in the message body.

Would it be possible to assign the local machine the same public IP 
address as the firewall?  That way, we would get the following:

Firewall's external network NIC has IP address A, which is visible to the 
outside world.

On the internal network we have:
Firewall's internal network NIC with private address X.
Machine needing to use Kerberos with address A.
Other machine with private address Y.

In theory, this looks like it should work.  The firewall machine shouldn't 
care what addresses are used internally.  It should just change the IP 
address and write the packet to the NIC for the internal network.  
However, is this how the software actually works?

-Dan Kiskis
[EMAIL PROTECTED]

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to