/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Sounds like you're mostly looking to do routing, with masq just a side note,
and certainly the "easy" part of this configuration. I think I might be
able to set it up, but I'd suggest that you head down to your local
technical book store, and try to find a good book on IP routing. I don't
see anything that can't be done, just things that are dificult, or at least
challenging. I don't have the kind of "free" time to do that, but if you
want to hire somebody, we could probably work something out <wink>.
Seriously though, that's mostly some ugly routing, and reading the ipchains
man pages and howto about 3 or 4 times, and you should be able to figure it
out on your own. Print out the ipchains man pages, you WILL need them as a
reference, and unless you have a multi-head machine, online just doesn't cut
it.
Greg
> -----Original Message-----
> From: Ashley M. Kirchner [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, March 22, 2000 5:07 PM
> To: [EMAIL PROTECTED]
> Subject: [Masq] Complicated perhaps?
>
>
> /* HINT: Search archives @ http://www.indyramp.com/masq/
> before posting! */
>
>
> This is an idea I've been toying with for a while and I
> can't really
> figure out what I want to do yet, but more important, if it can be
> done. Ideally, this is what the end result would look like
> (sorry if it
> gets rewrapped):
>
> =================>[ ROUTER ]
> ISP T1 w/ 1| |2
> 3 diff. IP | |
> ranges | |port 2 ___________________
> | +-------[eth1 eth3]--->[ HUB 0 ]->
> | [ firewall ]
> +-----------[eth0 machine eth2]--->[ HUB 1 ]->
> port 1 [___________________]
>
>
> Here's what I'd like to do:
>
> Our router accepts different ranges of IPs, which is also what our
> ISP has allocated to us. I have three different subnets, two of them
> coming on port 1, and the third one on port 2. One has only a few IPs
> in it, the other two have larger amounts.
>
> I'd like to have a firewall machine in there so that I can filter
> out packets coming into (as well as going out of) our
> networks, and more
> so, the specific PORT they're coming on. Based on that data, they'll
> get spit back out to the respective HUB, where there's a masq machine
> waiting to receive/respond.
>
> What I'd like to ask is, whether this is even possible. What are
> the possible problems I will face with this setup.
>
> A few things we run in house are, 5 DNS' and 3 WWW servers which
> also serve as FTP servers. ONE of the IP ranges on port 1 has its
> reverse lookup set at our ISP. The other TWO ranges are managed in
> house through Classless IN-ADDR.ARPA delegation (RFC2317 -
> ftp://ftp.isi.edu/in-notes/bcp/bcp20.txt). And I have some other
> daemons running that need specific ports opened.
>
> So. Is this possible? If so, how would I go by setting up the
> firewall machine. Ideally I would like to have eth3 and eth4 be
> 192.168.x.x subnets, but they also have to be able to talk to
> each other
> (meaning a machine sitting on one should be able to see a machine
> sitting on the other). Requests coming in on eth0 should be routed to
> the respective machine on eth3/4 (depending on how I delegate it), and
> the same goes for eth1.
>
> Also, does the firewall machine have to be something big and
> powerful to be able to disassemble those packets and figure
> out what to
> do with them?
>
> AMK4
>
> --
> W |
> | Digital information lasts forever, or five years
> | - whichever comes first.
>
> |____________________________________________________________________
>
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> Ashley M. Kirchner <mailto:[EMAIL PROTECTED]> .
> 303.442.6410 x130
> SysAdmin / Websmith .
> 800.441.3873 x130
> Photo Craft Laboratories, Inc. . eFax
> 248.671.0909
> http://www.pcraft.com . 3550
> Arapahoe Ave
> .................. . . . .
> Boulder, CO 80303
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> Admin requests can be handled at
http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.