/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Jiri Kucik wrote: > On Tue, 2 May 2000, raf wrote: > > > > I have a Linux box with one external (eth0) and one internal > > > (eth1) interfaces, both with one virtual interface (eth0:0 on the eth0 and > > > eth1:0 on the eth1). Are these commands enough to masq two internal > > > networks to two different external interfaces? > > > > > > ipchains -A forward -j MASQ -i eth0 -s eth1_network_address > > > ipchains -A forward -j MASQ -i eth0:0 -s eth1:0_network_address > > > > > > I've tried it but the second masq doesn't work - why? > > > > firstly, ipchains cannot distinguish between two "virtual" > > interfaces. there's no such thing as a virtual interface. > > they are just multiple addresses on the same interface. > > an interface can have multiple addresses from the same or > > different address families. it's still a single interface. > > so eth0 and eth0:0 are identical as far as the -i option > > is concerned. it's only the addresses that distinguish them. > > > > secondly, i don't think that the -i option means anything > > when used with the forward chain. at least, if it does, > > i've no idea whether it is supposed to refer to the interface > > on which the packet arrived or the interface on which it will > > leave (i suppose it's the former but it's not clear to me). > > forwarding has nothing to do with with eth0 or eth1. > > > > i don't even think iproute2 and fwmark-based port natting > > (as per the message i just sent) will help here since this > > is m:1 * 2, not 1:1 with some fiddling. > > I see. Thnx for your nice explanation. > > > sorry i can't think of a ($0) way to make this work but maybe > > someone else can. why do you want this setup, btw? for > > accounting purposes? > > Exactly. > > > maybe you need two external interfaces and two internal interfaces plus > > policy routing > > Impossible, since I need more than two ext and two internal > interfaces. And it is quite difficult to fit more than five or six of > NICs to the standard PC... > > > or two externally connected hosts with two interfaces each and no > > policy routing. > > Impossible. > > Anyway, thanks for your help. i think you should be able to masquerade all internal hosts behind a single public ip address and still do separate accounting for particular internal networks by using the iproute2 package from ftp.inr.ac.ru and assigning the separately accounted internal networks to different realms. raf _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
