/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I see.  Sorry for asking a question that is already in the HOWTO.  I must 
have missed it when reading the HOWTO the first time.  Guess I'll have to
get another NIC if I want to do this...

Thanks again!

Craig


On Sat, 22 Jan 2000, Shahid Sheikh wrote:

> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> 
> 
> Ahh! Sorry for misleading you earlier. This cannot be done. Have a look at
> this http://members.home.net/ipmasq/ipmasq-HOWTO-1.80-7.html#ss7.23
> 
> Shahid
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> Of Craig Baird
> Sent: Saturday, January 22, 2000 2:03 PM
> To: Shahid Sheikh
> Cc: [EMAIL PROTECTED]
> Subject: RE: [Masq] masq'ing to different external addresses
> 
> 
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> 
> 
> I think so.  As a test, here's what I set up:
> 
> On eth0 (my external IP), I have the address 192.168.0.5.
> On eth0:1 (the aliased IP), I have the address 192.168.0.33
> 
> I have two other NICs in the machine to run masq'ed networks:
> 
> eth1 has the address 10.0.7.1
> eth2 has the address 10.0.8.1
> 
> I have 10.0.7.0 network set up to masqerade as 192.168.0.5 (eth0). This
> seems to be working fine.
> 
> I want 10.0.8.0 to masqerade as 192.168.0.33, the virtual IP on eth0:1.
> 
> I can't seem to get it to masqerade to the virutal IP.  With the way I
> have it set up, I get "destination net unreachable" when I try to ping
> anything outside the internal network.
> 
> Here's what I have in rc.firewall in regard to the virutal IP (note that I
> am using kernel 2.0.36 and ipfwadm):
> 
> /sbin/ipfwadm -I -a accept -V 10.0.8.1 -S 10.0.8.0/24 -D 0.0.0.0/0
> 
> /sbin/ipfwadm -I -a accept -V 192.168.0.33 -S 0.0.0.0/0 -D 192.168.0.33/24
> 
> /sbin/ipfwadm -O -a accept -V 10.0.8.1 -S 0.0.0.0/0 -D 10.0.8.0/24
> 
> /sbin/ipfwadm -O -a accept -V 192.168.0.33 -S 192.168.0.33/32 -D 0.0.0.0/0
> 
> /sbin/ipfwadm -F -a masquerade -V 192.168.0.33 -S 10.0.8.0/24 -D 0.0.0.0/0
> 
> I don't think it's a problem with the rules because I'm not getting
> anything logged.
> 
> Thanks for any help that you can provide.
> 
> Craig
> 
> 
> 
> On Sat, 22 Jan 2000, Shahid Sheikh wrote:
> 
> > >From what little I understand about how the IP aliasing and IPCHAINS
> works,
> > I dont see any reason why it wouldn't work. Never tried it myself though.
> > Are you sure that you have an ipchains input rule to not reject any
> packets
> > coming to the aliased IP?
> >
> > Shahid
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> > Of Craig Baird
> > Sent: Thursday, January 20, 2000 8:04 PM
> > To: [EMAIL PROTECTED]
> > Subject: [Masq] masq'ing to different external addresses
> >
> >
> > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting!
> */
> >
> >
> > I have a situation where I have a masq'ed network, and the customer needs
> > one of his machines to appear to the outside world with a different IP
> > than the rest of his network.  The reason for this is that he connects
> > from this machine via telnet to a machine on the Internet that requires
> > him to have a static IP.  They could set it up to give access to our
> > external IP address, but then that would give his entire network access,
> > which he doesn't want.  He needs just that one machine to appear on the
> > Internet with a different IP address.  Is there an easy way to accomplish
> > this?
> >
> > I thought about the possibility of using a virtual IP address bound
> > to the same ethernet card as my external IP, and using ipfwadm to
> > masquerade his internal address as the virtual IP.  I tried it, and
> > couldn't seem to make it work.  Has anyone done anything like this before?
> >
> > Craig
> >
> > _______________________________________________
> > Masq maillist  -  [EMAIL PROTECTED]
> > Admin requests can be handled at http://www.indyramp.com/masq-list/ --
> THIS
> > INCLUDES UNSUBSCRIBING!
> > or email to [EMAIL PROTECTED]
> >
> > PLEASE read the HOWTO and search the archives before posting.
> > You can start your search at http://www.indyramp.com/masq/
> > Please keep general linux/unix/pc/internet questions off the list.
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
> INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
>UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to