/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ I have the following setup Redhat Linux 6.2 stock. Internal eth0 10.60.1.254 10.60.1.0/24 External eth1 123.123.123.210 123.123.123.208/29 (valid ips, but changed) DMZ eth2 123.123.123.217 123.123.123.216/29 default gw is 123.123.123.209 routing table is like so 123.123.123.210 0.0.0.0 255.255.255.255 UH 0 0 0 eth1 123.123.123.217 0.0.0.0 255.255.255.255 UH 0 0 0 eth2 10.60.1.254 0.0.0.0 255.255.255.255 UH 0 0 0 eth0 123.123.123.208 0.0.0.0 255.255.255.248 U 0 0 0 eth1 123.123.123.216 0.0.0.0 255.255.255.248 U 0 0 0 eth2 10.60.1.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0 127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo 0.0.0.0 123.123.123.209 0.0.0.0 UG 0 0 0 eth1 I want to be able to allow the following traffic MASQ all internal to external traffic MASQ all internal to DMZ traffic forward (without masqing) all traffic from external to DMZ MASQ specific traffic from DMZ to internal i have setup the following simple rule set to test this. Chain input (policy ACCEPT: 1016316 packets, 726954476 bytes): Chain forward (policy ACCEPT: 609 packets, 82314 bytes): target prot opt tosa tosx ifname mark outsize source destination ports MASQ all ------ 0xFF 0x00 any 10.60.1.0/24 anywhere n/a ACCEPT all ------ 0xFF 0x00 any anywhere 63.97.217.216/29 n/a Chain output (policy ACCEPT: 980562 packets, 723438697 bytes): Now, all traffic from the inside works fine, but I can not get to the dmz from an external source. What am I missing? Any other suggestions? Thanks in advance! Ryan _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
