/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Did you enable 'ICMP masquerading' when you compiled your kernel?  You
need this enabled to be able to correctly use a machine behind your ipmasq
server to ping a machine outside of it.

As long as the client machines are setup to use your ipmasq server as
their default gateway, then they should never send messages directly to
your router.  If any of your client machines are linux boxes, you can run
'/sbin/route' to see the routing table.. that should let you know if the
box is trying to use something else as its gateway.

On Tue, 11 Jan 2000, Dmitriy Stepanenko wrote:

> When I'm trying to ping some host in the corporate net from some host on the
> LAN (which is not permitted to traverse the corporate firewall) immediately
> after it came up, the first packet passes the firewall but all the
> subsequent do not. I beleive that when Linux receives the first packet it
> forwards it properly but it also answers to the pinging host (perhaps with
> ICMP Redirect packet - I am not familar enough with IP protocol details)
> that there is the shorter route to the corpnet - directly through 10.8.6.1.
> And the subsequent ping packets use this shorter way and are filtered out
> because they were not masqeraded.
> 
> So now I ask: can I do something to make the hosts on LAN use the Linux box
> as a gateway (masqerading) to corporate net. Disabling all outgoing ICMP
> Redirect packets seems to be too drastic measure (and I don't even know
> would
> it help and is it possible at all). I cannot change the IP address to all
> the LAN host (to move them to another subnet) because many of them use the
> "unmasqeradable" protocols (such as SMB). And I cannot move to another
> subnet just some of them because all the hosts on the LAN must communicate
> to
> each other.
> 
> So can anybody advise me what to do?
> 
> Thanks.
> ________________________________
> Dmitriy Stepanenko aka Mudropolk
> e-mail: [EMAIL PROTECTED]
> phone:  (380)(06264)1-93-06, local 41-93-06
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
>UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
> 

-- 

        Who wills,
        Can.
        Who tries,
        Does.
        Who loves,
        Lives.
                        --Anne McCaffery

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to