/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hello,

There's an example in the latest IP Masquerading HOWTO about the IPChains
ruleset to use if you have two internal nets that you need to masquerade.
Here's what it says:

  #Enable internal interfaces to communication between each other
  /sbin/ipchains -A forward -i eth1 -d 192.168.1.0/24
  /sbin/ipchains -A forward -i eth2 -d 192.168.0.0/24

  #Enable internal interfaces to MASQ out to the Internet
  /sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.0.0/24 -d 0.0.0.0/0
  /sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.1.0/24 -d 0.0.0.0/0

What if my Internet connection is an interface that isn't always present,
i.e. ppp0?  Would it still work if I just left the "-i eth0" out of the
last two lines?

Also, I don't really understand the IPChains syntax -- for example, does
the "-i" option mean "apply this rule to any packets received on said 
interface"?  Or does it specify a TARGET for forwarding any packets that
meet the source/destination parameters of the given rule? 

In the first two rules, it seems like "-i eth1" and "-i eth2" are the
interfaces on which the packets are received, but in the last two, it
seems like "-i eth0" is the destination since it's the gateway to the
Internet.

Right now I only have one internal network that I'm masquerading out
to the Internet via PPP, but I'm trying to figure out how this would all
work out if I were to add a second internal net (wireless LAN).

Thanks,
Chris Eng

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to