/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I have a server running RH 6.0 with kernel 2.2.13.  It has three 
ethernet cards.  Two connect to the internet and one for the 
internal lan.  I set it up exactly as shown in the HOWTO.  

Here is the configuration:

/sbin/ipchains -P input ACCEPT
/sbin/ipchains -P output ACCEPT
/sbin/ipchains -P forward REJECT

ipchains -A forward -i eth2 -j MASQ
ipchains -A forward -i eth1 -j MASQ

ip route add table 101 via 2.2.2.200
ip route add table 102 via 1.1.1.200

ip rule add from 192.168.1.0/24 to 192.168.1.0/24 table main pref 100
ip rule add from 192.168.1.8/32 to 0/0 table 101 pref 102
ip rule add from 192.168.1.0/24 to 0/0 table 102 pref 102

The packets do get routed according to the tables.  The problem is 
that return packets don't get demasqueraded on some connections.  
The packets always go to the gateway specefied in table 101 or 102 
and are masqueraded.  But if the table that routes the packet out 
doesn't agree with the main table about where to route the packet 
then the returning packets are not demasquraded.  For example 
because the default route in the main table points over line one, 
the clients routed over the first line work but the one routed over 
the line second doesn't. If I change the default route in the main 
table to point over the second line then the second line client 
works and the first line clients don't.  If I add a the following 
route:

route add -host 204.71.202.160 gw 2.2.2.200

then the clients using the second line can then ping and telnet to 
204.71.202.160 but clients using the first line can't.  Is this a masquerading
problem or a policy routing problem? If it isn't a masquerading problem what
would be the right list to post to about it?
I need to get these both up at the same time. Any help would be apreciated.  

Andy





____________________________________________________________________
Get free email and a permanent address at http://www.netaddress.com/?N=1

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to