/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Jiri Kucik wrote:

> On Mon, 1 May 2000, Derek Murphy wrote:
> 
> > > What about masquerading internal users out different _virtual_ interfaces
> > > (IP aliases) on the same external interface? 
> > 
> > A virtual or a physical i/f doesn't make any difference. What counts is the
> > ROUTING, and of course, the ipchains rules to allow/deny/reject from/to the 
> > different addresses/networks...
> 
> I have a Linux box with one external (eth0) and one internal 
> (eth1) interfaces, both with one virtual interface (eth0:0 on the eth0 and
> eth1:0 on the eth1). Are these commands enough to masq two internal
> networks to two different external interfaces?
> 
>   ipchains -A forward -j MASQ -i eth0 -s eth1_network_address
>   ipchains -A forward -j MASQ -i eth0:0 -s eth1:0_network_address
> 
> I've tried it but the second masq doesn't work - why?

firstly, ipchains cannot distinguish between two "virtual"
interfaces. there's no such thing as a virtual interface.
they are just multiple addresses on the same interface.
an interface can have multiple addresses from the same or
different address families. it's still a single interface.
so eth0 and eth0:0 are identical as far as the -i option
is concerned. it's only the addresses that distinguish them.

secondly, i don't think that the -i option means anything
when used with the forward chain. at least, if it does,
i've no idea whether it is supposed to refer to the interface
on which the packet arrived or the interface on which it will
leave (i suppose it's the former but it's not clear to me).
forwarding has nothing to do with with eth0 or eth1.

i don't even think iproute2 and fwmark-based port natting
(as per the message i just sent) will help here since this
is m:1 * 2, not 1:1 with some fiddling.

sorry i can't think of a ($0) way to make this work but maybe
someone else can. why do you want this setup, btw? for
accounting purposes? maybe you need two external interfaces
and two internal interfaces plus policy routing or two
externally connected hosts with two interfaces each and no
policy routing.

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to