/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Sorry been busy with other stuff, and I haven't slept in days.  :-)

> -----Original Message-----
> From: David A. Buechler [mailto:[EMAIL PROTECTED]]
> Sent: Monday, March 20, 2000 12:59 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [Masq] IP Masquerading and Cisco 1602 Routers
> 
> 
> /* HINT: Search archives @ http://www.indyramp.com/masq/ 
> before posting! */
> 
> 
> Greg,
> 
> >From the router(s) I can ping the local address without 
> difficulty.  The
> public address is another matter entirely.  I am including 
> the configs now.
> 
> IP MASQ:
> ipchains -F input
> ipchains -F output
> ipchains -F forward

Flush anything from the chains

> ipchains -P input ACCEPT
> ipchains -P output ACCEPT

Input and output default to accept

> ipchains -P forward DENY

Forward defaults to deny

> ipchains -A forward -i eth0 -j MASQ

add a rule to the forward chain, on the eth0 interface, MASQ those machines.
Whoops.  From 'man ipchains':

       -i, --interface [!] name
              Optional name of an interface via which a packet is received
(for  packets  entering
              the  input  chain),  or via which is packet is going to be
sent (for packets entering
              the forward or output chains).  When this option is  omitted,
the  empty  string  is
              assumed,  which  has  a special meaning and will match with
any interface name.  When
              the "!"  argument is used before the interface name, the sense
is inverted.   If  the
              interface  name  ends  in  a "+", then any interface which
begins with this name will
              match.

If you'll note, it says that in the FORWARD chain, it is the interface via
which the packet is goes to be sent.  This is just to make sure that you
know exactly what that rule is going.

I'm going to try to draw a nice little ascii art here, and tell me where I'm
wrong.  
                        
                        ----------
                        |INTERNET|
                        ----------
                                |
                                |
                        -----------------------
                        | eth0: a.b.c.d       |
                        | Linux Masq Box            |
                        | eth1: ??.??.??.??   |
                        -----------------------
                                |
                                |
                        ----------------------------
                        | ethernet0: 172.16.1.254  |
                        | Phoenix Router                   |
                        | Serial0:   172.16.40.254 |
                        ----------------------------
                                |
                                |
                        ----------------------------
                        | serial0: 172.16.40.253   |
                        | Tuscon Router            |
                        | ethernet0: 172.16.50.253 |
                        ----------------------------
                                |
                                |
                        -----------
                        | clients |
                        -----------

You probably have clients on the phoenix end (assuming that I have that
diagram drawn correctly), but since I don't know how things are layed out
there, I can't draw them in.  Since I know nothing about EIGRP, I'm not
going to try to figure out if you have routing correct.  Let me know where I
have things fouled up in this diagram, and we'll go from there.
        Greg

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to