/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ My question is similar to the thread on masqing real IP addresses, but with a bit of a twist. We recently got cable modem at home with a single assigned IP address. We are seriously considering setting up a Linux firewall system with our various home machines behind it. The firewall would be a normal configuration with two NICs, one connected to the cable modem and one to the internal network. One of the machines that we are going to have on the local network needs to be able to establish a Kerberos5 connection with a remote machine. Kerberos packs the IP address of the sending machine into the messsage body in addition to the IP address in the message header. These have to match for the receiving machine to accept the message. Thus, we can't give the local machine a private IP address because the IPmasqed address in the message header will be that of the firewall machine and will be different from the private address in the message body. Would it be possible to assign the local machine the same public IP address as the firewall? That way, we would get the following: Firewall's external network NIC has IP address A, which is visible to the outside world. On the internal network we have: Firewall's internal network NIC with private address X. Machine needing to use Kerberos with address A. Other machine with private address Y. In theory, this looks like it should work. The firewall machine shouldn't care what addresses are used internally. It should just change the IP address and write the packet to the NIC for the internal network. However, is this how the software actually works? -Dan Kiskis [EMAIL PROTECTED] _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
