/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! /* ALSO: Don't quote this header. It makes you look lame :-) */ Hello MASQers! Welp, I have just posted another substantial update to the MASQ HOWTO. Lots of both critical and ease-of-use changes in here and I hopefully met the deadline for the newest LDP doc. As always, you can find the newest version of the HOWTO at: http://www.ecst.csuchico.edu/~dranch/LINUX/index-linux.html#ipmasq and at the IPMASQ WWW site: http://ipmasq.cjb.net And as always.. at the LDP: http://www.linuxdoc.org --David =============================================================================== Changes from 1.90 to 1.95 - 11/14/00 - Added a quick upfront notice in the intro that running a SINGLE NIC in MASQ mutliple ethernet segments is NOT recommended and linked to the relivant FAQ entry. Thanks to Daniel Chudnov for helping the HOWTO be more clear. - Added a pointer in the Intro section to the FAQ section for users looking for how MASQ is different from NAT and Proxy services. - Reordered the Kernel requirements sections to be 2.2.x, 2.4.x, 2.0.x - Expanded the kernel testing in Section 3 to see if a given kernel already supports MASQ or not. - Reversed the order of the displayed simple MASQ ruleset examples (2.2.x and 2.0.x) - Cleaned up some formatting issues in the 2.0.x and 2.2.x rc.firewall files - Noted in the 2.2.x rc.firewall that the defrag option is gone in some distro's proc (Debian, TurboLinux, etc) - Added a NOTE #3 to the rc.firewall scripts to include instructions for Pump. Thanks to Ross Johnson for this one. - Cleaned up the simple MASQ ruleset examples for both the 2.2.x and 2.2.x kernels - Updated the simple and stronger IPCHAINS and IPFWADM rulesets to include the external interface names (IPCHAINS is -i; IPFWADM is -W) to avoid some internal traffic MASQing issues. - Vastly expanded the Section 5 (testing) with even more testing steps with added complete examples of what the output of the testing commands should look like. - Moved the H.323 application documentation from NOT supported to Supported. :) - Reordered the Multiple LAN section examples (2.2.x then 2.0.x) - Made some additional clarifications to the Multiple LAN examples - Fixed a critical typo with multiple NIC MASQing where the network examples had the specified networks reversed. Thanks to Matt Goheen for catching this. - Added a little intro to MFW in the PORTFW section. - Reveresed the 2.0.x and 2.2.x sections for PORTFW - Updated the news regarding PORTFWing FTP traffic for 2.2.x kernels NOTE: At this time, there *IS* a BETA level IP_MASQ_FTP module for PORT Forwarding FTP connections 2.2.x kernels which also supports adding additional PORTFW FTP ports on the fly without the requirement of unloading and reloaded the IP_MASQ_FTP module and thus breaking any existing FTP transfers. - Added a top level note about PORTFWed FTP support - Added a noted to the 2.0.x PORTFW'ed FTP example why users DON'T need to PORTFW port 20. - Updated the PORTFW section to also mention that users can use FTP proxy applications like the one from SuSe to support PORTFWed FTP-like functionality. Thanks to Stephen Graham for this one. - Updated the example for how to enable PORTFWed FTP to also include required configurations to how the ip_masq_ftp module is loaded for users who use multiple PORTs to contact multiple internal FTP servers. Thanks to Bob Britton for reminding me about this one. - Added a FAQ entry for users who have embedded ^Ms in their rc.firewall file - Expanded the FAQ entry talking about how MASQ is different from NAT and Proxy to include some informative URLs. - Updated the explanation of the MASQ MTU issue and describe the two main explanations of the issue. - Clarified that per the RFC, PPPoE should only require an MTU of 1490 though some ISPs require a setting of 1460. Because of this, I have updated the example to show an MTU of 1490. - Broke out the Windows 9x sections into Win95 and Win98 as they use different settings (DWORD vs. STRING). I also updated the sections to be more clear and the Registry backup methods have been updated. - Fixed a typo where the NT 4.0 Registry entries were backwards (Tcpip/Parameters vs. Parameters/Tcpip). - Fixed an issue where the WinNT entry should have been a DWORD and not a STRING. A serious thanks goes out to Geoff Mottram for his various PPPoE and various Windows Registry entry fixes. - Added an explicit URL for Oident in the IRC FAQ entry - Updated the FAQ section regarding some broken "netstat" versions - Added new FAQ sections for MASQ accounting ideas and traffic shaping - Expanded the IPROUTE2 FAQ entry on what Policy-routing is. - Moved the IPROUTE2 URLs to the 2.2.x Kernel requirements section and also added a few more URLs as well. - Corrected the "intnet" variable in the stronger IPCHAINS ruleset to reflect the 192.168.0.0 network to be consistent with the rest of the example. Thanks to Ross Johnson for this one. - Added a new FAQ section for people asking about forwarding problems between multiple internal MASQed LANs. - Added a new FAQ section about users wanting to PORTFW all ports from multiple external IP addresses to internal ones. I also touched on people trying to PORTFW all ports on multiple IP ALIASed interfaces and also noted the Bridge+Firewall HOWTO for DSL and Cablemodem users who have multiple IPs in a non-routed environment. - Added Mandrake 7.1, Mandrake 7.2, and Slackware 7.1 to the supported list - Added Redhat 7.0 to the MASQ supported distros. Thanks to Eugene Goldstein for this one. - Fixed a mathematical error in the "Maximum Throughput" calculation in the FAQ section. Thanks to Joe White @ [EMAIL PROTECTED] for this one. - Fixed the fact that the Windows9x MTU changes are a STRING change and not a DWORD change to the registry. Thanks to [EMAIL PROTECTED] for this one. - Updated the comments in the 2.0.x rc.firewall script to note that the ip_defrag option is for both 2.0 and 2.2 kernels. Thanks to [EMAIL PROTECTED] for this clarification. =============================================================================== .----------------------------------------------------------------------------. | David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] | !---- ----! `----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----' _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
