/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Chris Eng <[EMAIL PROTECTED]> wrote:
>
> Here's what it says:
>
> #Enable internal interfaces to communication between each other
> /sbin/ipchains -A forward -i eth1 -d 192.168.1.0/24
> /sbin/ipchains -A forward -i eth2 -d 192.168.0.0/24
Is this really what it says? Where's the target (-j option)? It should
have "-j ACCEPT", I should think. Otherwise these rules will have no
effect, other than to count traffic that matches.
> #Enable internal interfaces to MASQ out to the Internet
> /sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.0.0/24 -d 0.0.0.0/0
> /sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.1.0/24 -d 0.0.0.0/0
>
> What if my Internet connection is an interface that isn't always
> present, i.e. ppp0? Would it still work if I just left the "-i eth0"
> out of the last two lines?
You can simply go ahead and put "-i ppp0", even if that interface does
not exist. When the interface does exist, these rules will be able to
match traffic; when the interface doesn't exist, the rules will simply
fail to match, and thus, won't cause any masquerading to happen.
> Also, I don't really understand the IPChains syntax -- for example,
> does the "-i" option mean "apply this rule to any packets received on
> said interface"? Or does it specify a TARGET for forwarding any
> packets that meet the source/destination parameters of the given rule?
For the forward chain, it means "apply this rule to any packets trying
to forward OUT through said interface." Basically, the route table
chooses an interface to forward through, and then the forward chain is
called in order to determine if that is allowed, with or without
masquerading. It does NOT specify a target; the route table does that.
> In the first two rules, it seems like "-i eth1" and "-i eth2" are the
> interfaces on which the packets are received, but in the last two, it
> seems like "-i eth0" is the destination since it's the gateway to the
> Internet.
Since these rules operate on the forward chain, ALL of them are
specifying destinations. In other words, the first rule, specifies that
packets trying to reach eth1, going to destination address of
192.168.1.*, will be allowed to pass through. That means that, if some
clever hacker managed to send packets into your ppp0 interface, with a
destination IP of 192.168.1.*, they would indeed get forwarded to your
eth1 interface. Some additional input/output rules would be handy to
stop that from happening.
> Right now I only have one internal network that I'm masquerading out
> to the Internet via PPP, but I'm trying to figure out how this would
> all work out if I were to add a second internal net (wireless LAN).
I'm in the same situation here, migrating from a PPP interface to DSL.
But basically my scripts simply change from treating ppp0 as the
external interface, to treating eth2 as the external interface.
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience.
sometimes known as David DeSimone || Experience comes from bad judgment."
http://www.dallas.net/~fox/ || -- Life Lessons
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.