/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Robert T Butler III wrote:

>    I've successfully set up masq on a 486 running RedHat 6.1.  Everything
> seems to be working smoothly, though I'm still using the basic rule-set for
> ipchains.  I plan on setting up a stronger set of rules later.  My setup is
> simple.  I have a single private network (192.168.0.*) being masqueraded to
> the Internet.  What I want to do is be able to specify which Internet
> services my masqed workstations can access.  I.e., I would like to prevent
> some workstations from viewing web pages, some from reading newsgroups, some
> from receiving email, etc.  I believe I've given the IP Masq how-to a pretty
> thorough reading and I can't find any specific info about this, or maybe
> it's there, but just way over my head.  I would greatly appreciate it if
> someone could point me in a promising direction.

have a look at http://www.zip.com.au/~raf2/lib/software/firewall
for an example of how to do all of this. in short, for the external
interface, allow the services that any internal host might need to
access. then, for the internal interface(s), allow packets per host
per service as required (the packets won't be masqueraded on their
way in to the firewall/masquerading host and so they're easily
identified at that point).

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to