/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



>I need to know if its possible to forward ports to _internal_ host
>from
>_internal_ clients.
>
>RH 5.2 - Kernel 2.2.9 - IPCHAINS 1.3.9 - IPMASQADM 0.4.2 - TR0 and TR1
>(or
>TR0 and TR0:1)
>
>I'm simply trying, with two token ring cards, to forward a port from
>one
>machines to another on the same ring.
>
>I'm having trouble MASQing packets across the same subnet (167.16.1.x/24).
>When I put the IPCHAINS line in I have no idea what interface its going
>to.
>If I put in the following in chains:
>
>       [root@linux01 /root]# ipchains -L
>       Chain input (policy ACCEPT):
>       Chain forward (policy DENY):
>       target     prot opt     source                destination          
>ports
>       MASQ       tcp  ------  167.16.1.0/24        anywhere              any
>->
>any
>       MASQ       tcp  ------  anywhere             167.16.1.0/24         any
>->
>any

>I want telnet sessions pointed at machine 2 to be forwarded to machine
>3.
>
>Does ANYONE have any ideas?  I have also explored using virtual interfaces
>(aliases) with no success.
>
>Thanks for any help anyone can give.

It doesn't work with masquerading because the server on the internal network sees
the other internal IP, replies to it, but the client is expecting a reply from
the Linux gateway. The solution as you tried is double masquerading, but that
doesn't work as you tried it in ipchains because, when you send the SYN packet
to establish the connection, it is mangled already in the _input_ section of
the IP code, not the forward section (in general, masquerading for output from
imaginary IPs to real ones is in the forward code while demasq is in input).
This mangling causes it to bypass the forward section entirely.

I've posted a kernel patch today to linux-kernel and masq lists which allows
a single masq entry to code for bidirectional masquerading, and that works very
well on our internal network here at Helix. As an added benefit, you don't even
need to add MASQ lines to ipchains if you don't have them already.

The other option is to use a userspace program such as redir. That works too,
although it may be slower?


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to