/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Sounds like you're mostly looking to do routing, with masq just a side note,
and certainly the "easy" part of this configuration.  I think I might be
able to set it up, but I'd suggest that you head down to your local
technical book store, and try to find a good book on IP routing.  I don't
see anything that can't be done, just things that are dificult, or at least
challenging.  I don't have the kind of "free" time to do that, but if you
want to hire somebody, we could probably work something out <wink>.
Seriously though, that's mostly some ugly routing, and reading the ipchains
man pages and howto about 3 or 4 times, and you should be able to figure it
out on your own.  Print out the ipchains man pages, you WILL need them as a
reference, and unless you have a multi-head machine, online just doesn't cut
it.  
        Greg


> -----Original Message-----
> From: Ashley M. Kirchner [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, March 22, 2000 5:07 PM
> To: [EMAIL PROTECTED]
> Subject: [Masq] Complicated perhaps?
> 
> 
> /* HINT: Search archives @ http://www.indyramp.com/masq/ 
> before posting! */
> 
> 
>     This is an idea I've been toying with for a while and I 
> can't really
> figure out what I want to do yet, but more important, if it can be
> done.  Ideally, this is what the end result would look like 
> (sorry if it
> gets rewrapped):
> 
> =================>[ ROUTER ]
>    ISP T1 w/        1|   |2
>   3 diff. IP         |   |
>     ranges           |   |port 2  ___________________
>                      |   +-------[eth1           eth3]--->[ HUB 0 ]->
>                      |           [      firewall     ]
>                      +-----------[eth0  machine  eth2]--->[ HUB 1 ]->
>                         port 1   [___________________]
> 
> 
>     Here's what I'd like to do:
> 
>     Our router accepts different ranges of IPs, which is also what our
> ISP has allocated to us.  I have three different subnets, two of them
> coming on port 1, and the third one on port 2.  One has only a few IPs
> in it, the other two have larger amounts.
> 
>     I'd like to have a firewall machine in there so that I can filter
> out packets coming into (as well as going out of) our 
> networks, and more
> so, the specific PORT they're coming on.  Based on that data, they'll
> get spit back out to the respective HUB, where there's a masq machine
> waiting to receive/respond.
> 
>     What I'd like to ask is, whether this is even possible.  What are
> the possible problems I will face with this setup.
> 
>     A few things we run in house are, 5 DNS' and 3 WWW servers which
> also serve as FTP servers.  ONE of the IP ranges on port 1 has its
> reverse lookup set at our ISP.  The other TWO ranges are managed in
> house through Classless IN-ADDR.ARPA delegation (RFC2317 -
> ftp://ftp.isi.edu/in-notes/bcp/bcp20.txt).  And I have some other
> daemons running that need specific ports opened.
> 
>     So.  Is this possible?  If so, how would I go by setting up the
> firewall machine.  Ideally I would like to have eth3 and eth4 be
> 192.168.x.x subnets, but they also have to be able to talk to 
> each other
> (meaning a machine sitting on one should be able to see a machine
> sitting on the other).  Requests coming in on eth0 should be routed to
> the respective machine on eth3/4 (depending on how I delegate it), and
> the same goes for eth1.
> 
>     Also, does the firewall machine have to be something big and
> powerful to be able to disassemble those packets and figure 
> out what to
> do with them?
> 
>     AMK4
> 
> --
> W |
>   |  Digital information lasts forever, or five years
>   |   - whichever comes first.
>   
> |____________________________________________________________________
>   
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>   Ashley M. Kirchner <mailto:[EMAIL PROTECTED]>   .   
> 303.442.6410 x130
>   SysAdmin / Websmith                           .     
> 800.441.3873 x130
>   Photo Craft Laboratories, Inc.             .        eFax 
> 248.671.0909
>   http://www.pcraft.com                  .            3550 
> Arapahoe Ave
>   .................. .  .  .     .                    
> Boulder, CO 80303
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at 
http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to