/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


|BoRiS| wrote:

> Is it possible to use IP-MASQ with IP-ALIAS ?
> and HOW ?

yes, it is possible but not well documented. getting packets
in isn't a problem but making the reply packets come out on
the right alias is tricky. it's a routing thing, not a
masquerading thing.

you need the iproute2 package. it's in moscow on a 386 but
there are mirrors for it. read the masquerading howto and
the ip command reference and then try something like:

say you have some real ip addresses: 222.222.222.168-175
and they are aliased onto your public interface (ppp0)
and your internal network is 10/8 via eth0 and you want:

  222.222.222.169:80 <-> 10.0.0.1:80 (web server)
  222.222.222.170:25 <-> 10.0.0.2:25 (smtp server)
  222.222.222.171:22 <-> 10.0.0.2:22 (ssh server)

you would need to do something like:

  # Prepare for portforwarding by invoking masquerading

  ipchains -A forward -p tcp -s 10.0.0.1 80 -j MASQ
  ipchains -A forward -p tcp -s 10.0.0.2 25 -j MASQ
  ipchains -A forward -p tcp -s 10.0.0.2 22 -j MASQ

  # Rewrite the destination address of incoming packets

  ipmasqadm portfw -a -P tcp -L 222.222.222.169 80 -R 10.0.0.1 80
  ipmasqadm portfw -a -P tcp -L 222.222.222.170 25 -R 10.0.0.2 25
  ipmasqadm portfw -a -P tcp -L 222.222.222.171 22 -R 10.0.0.2 22

  # Mark outgoing packets that need to have their source addresses
  # rewritten by ip

  ipchains -A input -i eth0 -p tcp -s 10.0.0.1 80 -m 80
  ipchains -A input -i eth0 -p tcp -s 10.0.0.2 25 -m 25
  ipchains -A input -i eth0 -p tcp -s 10.0.0.2 22 -m 22

  # Rewrite their source addresses

  ip rule add fwmark 80 nat 222.222.222.169
  ip rule add fwmark 25 nat 222.222.222.170
  ip rule add fwmark 22 nat 222.222.222.171

this is only a subset of the things you might want to do through aliases
but it's a start and it works for me and it demonstrates the fundamental
technique that is required. please let me know if this helps. if you have
problems getting it working and you solve them, i'd like to hear about it.

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to