/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hi again!

Funny thing that David asked about what I thought of the documentation.  I
decided I really didn't have a good opinion, so I went back to snafu.freedom.org
and re-read the NAT section of the ip-cref document.  I find, in bold, "How to
translate only selected ports" in the appendix.

My original problem was that after issuing a nat rule against a particular
source address, packets arriving from that source would no longer appear to
traverse the forward chain, they would automagically masq out on the specified
nat address.  My intention was to have "fascist" masqing rules, specifically
allowing only certain ports to be masq'ed, and this completely circumvented all
the work I had done on my IP chains forward rules.

So I see another rule type, using fwmark as a key to activating nat.  Sounds
like I can regain control of the natting by marking packets on my input chain
(for my LAN-side interface), then issuing "ip ru add fwmark <x> nat <nat-addr>"
where <x> corresponds to the selected mark.

This doesn't seem all that different from my previous arrangement, so I did not
reintroduce the masq rules that I had removed upon discovering that they weren't
even being traversed.  I try to ssh out, packet denied in forwarding!  Seems all
of a sudden, these packets _are_ hitting the forward chain.  I put the rule
back, ssh out, verify my netstat to the "aliased masq", and all is well!
Packets are now logged twice, once on the LAN side input (to mark), then on the
"fascist" masqs in the forward chains, and I've really got to reorganize all
these rules somehow for clarity, but I believe this has solved this issue for
the time being.  Anybody see any problems with this?

David - I did only look at the documentation relevant to the rule mechanisms of
iproute2, but I suppose if someone as dense as I could figure out how to do
this, it must be pretty good!

- Dardo D Kleiner
Software Product Engineer
CIPS, Corp.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to