/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hi again! Funny thing that David asked about what I thought of the documentation. I decided I really didn't have a good opinion, so I went back to snafu.freedom.org and re-read the NAT section of the ip-cref document. I find, in bold, "How to translate only selected ports" in the appendix. My original problem was that after issuing a nat rule against a particular source address, packets arriving from that source would no longer appear to traverse the forward chain, they would automagically masq out on the specified nat address. My intention was to have "fascist" masqing rules, specifically allowing only certain ports to be masq'ed, and this completely circumvented all the work I had done on my IP chains forward rules. So I see another rule type, using fwmark as a key to activating nat. Sounds like I can regain control of the natting by marking packets on my input chain (for my LAN-side interface), then issuing "ip ru add fwmark <x> nat <nat-addr>" where <x> corresponds to the selected mark. This doesn't seem all that different from my previous arrangement, so I did not reintroduce the masq rules that I had removed upon discovering that they weren't even being traversed. I try to ssh out, packet denied in forwarding! Seems all of a sudden, these packets _are_ hitting the forward chain. I put the rule back, ssh out, verify my netstat to the "aliased masq", and all is well! Packets are now logged twice, once on the LAN side input (to mark), then on the "fascist" masqs in the forward chains, and I've really got to reorganize all these rules somehow for clarity, but I believe this has solved this issue for the time being. Anybody see any problems with this? David - I did only look at the documentation relevant to the rule mechanisms of iproute2, but I suppose if someone as dense as I could figure out how to do this, it must be pretty good! - Dardo D Kleiner Software Product Engineer CIPS, Corp. _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
