/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hello all,

I am running vmware 1.1.2 on a brand new RedHat 6.1 install (pump
replaced with dhcpcd) and can't seem to convince masquerading to work
across the linux box.  Because of the parts of the network that I can
ping, I'll tenatively assume that the vmware portion of the network is
working properly and that the masquerading is somehow screwed up.

According to legend, a vmware machine on the internal network should 
act exactly like a separate machine connected to a second ethernet card.
In fact, the masquerading page on the vmware web site looks a lot like
the masquerading HOWTO.

Here's what works:

host machine can ping world
host machine can ping vmware machine
vmware machine can ping host machine (internal interface 172.*.*.*)

Here's what doesn't:

vmware machine cannot ping host machine (external interface 192.*.*.*)
vmware machine cannot ping world

Here are the results of the four tests from the HOWTO

# ifconfig
eth0      Link encap:Ethernet  HWaddr 00:50:04:5D:A8:96  
          inet addr:192.168.100.70  Bcast:192.168.100.255  Mask:255.255.255.0
          UP BROADCAST NOTRAILERS RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:163 errors:0 dropped:0 overruns:0 frame:0
          TX packets:6 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100 
          Interrupt:3 Base address:0x280 

lo        Link encap:Local Loopback  
          inet addr:127.0.0.1  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:3924  Metric:1
          RX packets:4 errors:0 dropped:0 overruns:0 frame:0
          TX packets:4 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 

vmnet1    Link encap:Ethernet  HWaddr 00:50:56:8A:00:00  
          inet addr:172.16.226.1  Bcast:172.16.255.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:482 errors:0 dropped:0 overruns:0 frame:0
          TX packets:21 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100 

# route
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
192.168.100.0   *               255.255.255.0   U     0      0        0 eth0
172.16.226.0    *               255.255.255.0   U     0      0        0 vmnet1
127.0.0.0       *               255.0.0.0       U     0      0        0 lo
default         192.168.100.254 0.0.0.0         UG    0      0        0 eth0


# cat /proc/sys/net/ipv4/ip_forward 
1

# ipchains -L
Chain input (policy ACCEPT):
target     prot opt     source                destination           ports
ACCEPT     udp  ------  anywhere             anywhere              bootps ->   bootpc
Chain forward (policy DENY):
target     prot opt     source                destination           ports
MASQ       all  ------  172.16.226.0/24      anywhere              n/a
Chain output (policy ACCEPT):


Here's my /etc/rc.d/init.d/firewall script (comments deleted).  This is
taken directly from the HOWTO and modified as described to handle DHCP
resolution of the masquerading machine.

#!/bin/sh

/sbin/depmod -a
/sbin/modprobe ip_masq_ftp

echo "1" > /proc/sys/net/ipv4/ip_forward
echo "1" > /proc/sys/net/ipv4/ip_dynaddr

/sbin/ipchains -M -S 7200 10 160

/sbin/ipchains -A input -j ACCEPT -i eth0 -s 0/0 67 -d 0/0 68 -p udp
/sbin/ipchains -P forward DENY
/sbin/ipchains -A forward -s 172.16.226.0/24 -j MASQ

All of my tests look fine according to the HOWTO.  But it still doesn't 
work.  Any help will be appreciated.

Regards,
Ross

-- Ross Bagley & Associates  http://www.rossbagley.com
"We don't write your software, we help you write your software better!"

-- Ross Bagley & Associates  http://www.rossbagley.com
"We don't write your software, we help you write your software better!"

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to