/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Woohoo! Got a reply!

>Curious, why did you go the packet label (mfw) route?  Personally, I
>think its an elegant way to do things but I've stuck with PORTFW.

When I looked at the alternatives (starting from scratch), mfw just seemed like
the logical way to do what I wanted.  I have looked at portfw, but have never
assessed its effectiveness versus the firewall marking method.  I wouldv'e said
"cool" (especially the load balancing stuff, even though I haven't actually used
it yet) instead of "elegant", but that's just because I lack social graces!

>There is a ALPHA ip_masq_ftp module that might fix this issue for you
>though I haven't heard a whole lot of infomation back from the
>testers.

I wouldn't expect passive FTP to ever work unless I voluntarily fwmark
everything above 1024: to go to my ftp server.  This is unacceptable however, so
I have pretty much given up on having that capability.

>Try doing the forwarding to a NON-Aliased IP address.  This might fix it.
>As it stands, MASQ does not always play well with ALIASed IPs.  Just try
>it and let us know.

Unfortunately, I do not have a machine with 3 NICs to test this for you.  Nor
can my primary firewall come down long enough to throw another card in (mission
semi-critical, I don't think I have a free slot either).  I convinced the boss
to let me put in the Linux firewall, now I have to do this testing/research as
delicately as I can.  Any other way I can help figure this out?

>PS.  What do you think of the IPROUTE2 package?  Difficult to figure out?
>Good/Bad documentation, etc

Hmmm...tough call...I can't say that I understand where the routes and rules of
iproute2 relate to the "standard" routes and ipchains rules (routing tables
already confuse the heck out of me).  This is one reason why I posted
originally.  I can't even relocate the place where I found the ru nat trick.
That's the only thing I've determined I _need_ iproute2 for so far, but I would
really like to understand it better in general.  I've read that this whole thing
has been redesigned for 2.3/2.4, will iproute2 and ipchains become a unified
tool?  This would help immensely, as I had finally figured out most of ipchains
when I found I needed to learn about another complex tool to get what I wanted.
Not to mention this whole ipmasqadm vs ipnatadm issue.  I've been using the masq
stuff the whole time, but I keep seeing people talking about ipnatadm and I
wonder which is "better", and which is going to be preferred in Linux's future.

Eagerly awaiting reply!
- Dardo D Kleiner
Software Product Engineer
CIPS, Corp.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to