/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
No, this would just send the internal address out into the world as 192.168.1.5. I
need to change it to an acceptable address that is not the MASQ address. Like
192.168.1.5 <--> 204.71.200.245, for instance while the masq'd address is
204.71.200.240. NAT would allow me to use an NT server for VPN w/o it having
hissy-fits because it would be in a different address map. I've tried this by doing
what you suggest, but it doesn't allow browsing, etc. It seems like NAT would be just
a short, natural extention of MASQ, which is why I posted the question after looking
all over and then finally installing the NAT-2.2.4 patch on 2.2.14. I'm now to the
point of doing yet another kernel -- 2.2.4 to see if it works any better with that.
Maybe it just doesn't work, but I've been building zillions of kernels for pptp, raid,
masq and have pretty much run out of energy and time to try a whole nother slew of
tests. But thanks for the suggestion!! -- Joe B.
At 12:17 PM 3/9/00 EST, Michael Best wrote:
>On 09 Mar 2000, Joe Beauchamp wrote:
>
>> I have several things running on a 2.2.14 kernel including VPN and using
>MASQ, however, I need one machine to get directly through with its IP address,
>so I found the NAT patches for 2.2.4 and installed them.
>
>Couldn't you just add a rule like this:
>
># pass packets from one computer through
>/sbin/ipchains -A forward -s 192.168.1.5/32 -j ACCEPT
>
># masq all others
>/sbin/ipchains -A forward -s 192.168.1.0/24 -j MASQ
>
>-- Michael Best
>
>
________________________________________________________________________
Joe Beauchamp -- VP, New Technology -- 4anything.com -- (610) 768-1444
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.