/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



On Mon, 5 Jul 1999, Pankaj Arora wrote:

> Well I tried it with the internal interface [one hooked up to hub]
> and it didn't work, I would assume the external one would work
> [hooked up to cable modem] but wouldn't that allow others to MASQ
> behind my box?  I'm probably just confused.  Thanks for your
> response and help. 

For forwarding rules you specify the interface the packet will go
*out* over.

"allowing others to masq behind your box" is the point of this, is it
not? That can be controlled by making the firewall rules more
specific. See my firewall generator for an example (ipfwadm, granted,
but the concepts still hold, and it can be converted to ipchains via 
a translator). 

  http://www.wolfenet.com/~jhardin/ipfwadm.html

You should also read the Masquerade HOWTO, it will explain a lot.

> > >Is there anyway I can tell ipchains to only Forward/MASQ on only a
> > >certain network device, such as eth0?
> >
> > Sure.. "-i eth0"

--
 John Hardin KA7OHZ                               [EMAIL PROTECTED]
 pgpk -a finger://gonzo.wolfenet.com/jhardin    PGP key ID: 0x41EA94F5
 PGP key fingerprint: A3 0C 5B C2 EF 0D 2C E5  E9 BF C8 33 A7 A9 CE 76 
-----------------------------------------------------------------------
  Efficiency can magnify good, but it magnifies evil just as well.
  So, we should not be surprised to find that modern electronic
  communication magnifies stupidity as *efficiently* as it magnifies
  intelligence.  
                                  -- Robert A. Matern
-----------------------------------------------------------------------
   66 days until 9/9/99



_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to