/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! /* ALSO: Don't quote this header. It makes you look lame :-) */ Hi all, This may be outside the scope of this mailing list, I have tried on the redhat list and had no answers. I know quite a few here are pretty handy with routing and firewalling, so here goes... I have a network behind a cable modem with a RH6.2 box doing firewalling, masq'ing, and portforwarding port 80 and 21 to an internal host. I'm moving my web/ftp server outside of the firewall, where it will be multihomed so that I can still run Samba, etc. on the internal side. Below is my poor attempt at ascii art: ***Cable Modem Gateway*** 777.777.777.1/22 | **CABLEMODEM** | ____________***HUB***_____________ | | eth1:777.777.777.2/22 eth0:777.777.777.193/22 **Webserver** **Firewall** eth0:192.168.0.10/24 _____HUB____eth1:192.168.0.1/24 | | ***Other internal workstations*** 192.168.0.x/22 gw 192.168.0.1 The Webserver does not have IP Forwarding enabled, the firewall (obviously) does. The firewall has very strict ipchains rules based off of David Ranch's TrinityOS rules. The webserver is also using strong ipchains sets, minus the forwarding rules. What I would like to have happen is for the webserver to respond to requests that are portforwarded from 192.168.0.1, as well as ones that are made directly to the .2 interface - until the DNS changes take effect -- after which I will remove the portforwarding rule on the firewall. I can think of a couple of solutions.... 1) The webserver to "knows" which interface the request came in on, and uses the appropriate gateway. For example, if the request comes in on eth1 (192.168.0.10) it needs to use 192.168.0.1 for its gateway, if the request comes in on 777.777.777.2, it needs to use 777.777.777.1 as its gateway. I have egress filters on the .1 firewall that disallow the webserver from using the firewall as it's default gw when the webserver uses it's .2 address. Am I describing the functions of the iproute2 package? Are there any quick and easy ways to accomplishing this using iproute2? I have no experience with the package. 2) Use a portforwarding utility like leapfrog at http://www.cotse.com/CotseLabs/leapfrog/leapfrog.htm to intercept port 80 requests at the firewall's .193 address and forward it to the webserver's .2 interface on port 80 and set one default gateway on the webserver pointing to 777.777.777.1. Again, I'm looking for a quick and dirty hack more than a permanent solution (while keeping the firewall effective) since this is only to keep websites working while DNS updates take effect. TIA, Justin _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
