/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Greg,
>From the router(s) I can ping the local address without difficulty. The
public address is another matter entirely. I am including the configs now.
IP MASQ:
ipchains -F input
ipchains -F output
ipchains -F forward
ipchains -P input ACCEPT
ipchains -P output ACCEPT
ipchains -P forward DENY
ipchains -A forward -i eth0 -j MASQ
Phoenix Router:
Building configuration...
Current configuration:
version 11.2
no service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname Router_Phx
!
interface Ethernet0
ip address 172.16.1.254 255.255.255.0
ip helper-address 172.16.50.1
!
interface Serial0
ip address 172.16.40.254 255.255.255.0
service-module 56k clock source line
service-module 56k network-type dds
!
router eigrp 1
redistribute connected
network 172.16.0.0
!
ip default-gateway 172.16.1.6
no ip classless
!
line con 0
line vty 0 4
login
!
end
Tucson Router:
Building configuration...
Current configuration:
!
version 11.2
no service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname Router_Tuc
!
interface Ethernet0
ip address 172.16.50.253 255.255.255.0
ip helper-address 172.16.1.3
!
interface Serial0
ip address 172.16.40.253 255.255.255.0
no fair-queue
service-module 56k clock source line
service-module 56k network-type dds
!
router eigrp 1
redistribute connected
network 172.16.0.0
!
no ip classless
!
line con 0
exec-timeout 0 0
line vty 0 4
exec-timeout 0 0
no login
!
end
Regards,
David A. Buechler
Support Services Coordinator,
Data Systems of Arizona, Inc.
Phoenix, Arizona
-- Linux: Because a 386 is terrible thing to waste. --
At 10:40 AM 3/20/00 -0800, you wrote:
>/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
>> -----Original Message-----
>> From: David A. Buechler [mailto:[EMAIL PROTECTED]]
>> Sent: Monday, March 20, 2000 10:02 AM
>> To: [EMAIL PROTECTED]
>> Subject: [Masq] IP Masquerading and Cisco 1602 Routers
>>
>>
>> /* HINT: Search archives @ http://www.indyramp.com/masq/
>> before posting! */
>>
>>
>> Overview:
>> Ok, I've got a pretty basic config. I am in Phoenix, my
>> branch office is
>> in Tucson. I have a 56k line running between them and two Cisco 1602s
>> (Cisco IOS 11.2) on each end. I also have a 56k line to the
>> Internet and a
>> linux server running IPMASQ as a network address translator.
>>
>> Problem:
>> >From the office, IPMASQ works beautifully. I've had no problems.
>> >From the routers, (and, consequently, from the Tucson
>> Office) I cannot see
>> the Internet. No pings; no telnets; no web traffic; nothing.
>> I can see
>> and hit everything on the local net, without fail. Chatted
>> with Cisco.
>> Cisco claims that the routers are set up correctly due to the
>> fact that I
>> am able to see everything on the local net and that the
>> problem must be
>> with my NAT server (the linux box).
>>
>> Questions:
>> 1.) Is Cisco lying to me to get me to pay for a support contract?
>
>Dunno, probably not. Cisco has been good as far as support for me so far.
>
>> 2.) If not, can this even be done? If it can, I'm assuming
>> you'd like to
>> look at my configs. I hope you can understand that I would
>> not like to
>> post them for the world to see, simple, as they may be. I
>> will, however,
>> email them upon request.
>
>Strip out the incriminating information from them and post to the list. For
>private IP address blocks, it doesn't matter, they're private, you can't get
>at them from elsewhere. For your external IP address/s make something up,
>like aaa.bbb.ccc.ddd, or my.external.ip.address. As for something helpful,
>can you ping the internal address of your linux masq computer? How about
>the external address of your linux masq computer?
> Greg
>
>_______________________________________________
>Masq maillist - [EMAIL PROTECTED]
>Admin requests can be handled at http://www.indyramp.com/masq-list/ --
THIS INCLUDES UNSUBSCRIBING!
>or email to [EMAIL PROTECTED]
>
>PLEASE read the HOWTO and search the archives before posting.
>You can start your search at http://www.indyramp.com/masq/
>Please keep general linux/unix/pc/internet questions off the list.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.