* [LARTC] Re: 3 interfaces in one linux box
@ 2002-07-12 20:55 bert hubert
2002-07-17 6:11 ` Géczi Szabolcs
2002-07-17 11:25 ` bert hubert
0 siblings, 2 replies; 3+ messages in thread
From: bert hubert @ 2002-07-12 20:55 UTC (permalink / raw)
To: lartc
On Fri, Jul 12, 2002 at 10:45:58PM +0200, G?czi Szabolcs wrote:
> Hello,
>
> first of all apologize for my bad english.
No problem.
> the facts :
> +-------+
> leased line------- eth0| Linux |
> | box |-eth1------subnet/switch ---clients, servers
> cablenetwork ----- eth2+-------+
>
>
> The eth0 interface has 5 aliased ip addresses which portforwarded to
> servers into subnet.
Ok. How is this forwarding performed? ipchains? rinetd?
> The eth2 interface has 1 ip address.
> The eth1 interface used for subnet.
> The linux box masquerades with ipchains (2.2.19 kernel).
The problems are:
* Making sure that the default gateway is the cablenet
* Except for sessions that went to the 5 aliased ip addresses on eth0,
which should have eth0 as their default gateway
I think this will be pretty easy with policy routing.
echo 200 leased >> /etc/iproute2/rt_tables
ip rule add from alias.1.ip.address table leased
ip rule add from alias.2.ip.address table leased
ip rule add from alias.3.ip.address table leased
ip rule add from alias.4.ip.address table leased
ip rule add from alias.5.ip.address table leased
ip route add default via leased.router.ip dev eth0 table leased
However, it *is* possible that this interferes with the aliases. Try this
and let us know!
See also http://lartc.org/howto/lartc.rpdb.html#LARTC.RPDB.SIMPLE
Regards,
bert
--
http://www.PowerDNS.com Versatile DNS Software & Services
http://www.tk the dot in .tk
http://lartc.org Linux Advanced Routing & Traffic Control HOWTO
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [LARTC] Re: 3 interfaces in one linux box
2002-07-12 20:55 [LARTC] Re: 3 interfaces in one linux box bert hubert
@ 2002-07-17 6:11 ` Géczi Szabolcs
2002-07-17 11:25 ` bert hubert
1 sibling, 0 replies; 3+ messages in thread
From: Géczi Szabolcs @ 2002-07-17 6:11 UTC (permalink / raw)
To: lartc
On Sat, Jul 13, 2002 at 12:54:02PM +0200, bert hubert wrote:
> > Great, a little corrections needed, the solution provided by ahu.
> > I did what bert wrote, but ahu adviced that I should write ip rule add from
> > internal.ip.address table leased, after that the servers in subnet can
> > answer. Thanks to Bert and ahu.
>
> Bert and <ahu> are one guy :-) This means that ipchains acts AFTER the
> policy table has been selected. iptables may well go BEFORE - be aware of
> that before upgrading.
[...]
>
> Try 'tcpdump -n -i interface' to see where packets go. They probably go out
> the wrong interface.
there are some additional problems with routing :).
So after I set up my iproute2 (ip rule add, ip route) my servers answer from
subnet, BUT the client from subnet can't reach the linuxbox's public
interface (217.65.110.146) and about this problem, they can't see the
webpage on the linux box. The internal ip address is available from subnet,
but the leased line's public interface cannot be reached.
any idea ?
--
Géczi Szabolcs
GPG: http://www.goodwill.hu/~szabszi/szabszi.asc
Fingerprint: B36C 150C C316 5A15 DB5F 183A 303B 5AEB 36C2 3162
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [LARTC] Re: 3 interfaces in one linux box
2002-07-12 20:55 [LARTC] Re: 3 interfaces in one linux box bert hubert
2002-07-17 6:11 ` Géczi Szabolcs
@ 2002-07-17 11:25 ` bert hubert
1 sibling, 0 replies; 3+ messages in thread
From: bert hubert @ 2002-07-17 11:25 UTC (permalink / raw)
To: lartc
On Wed, Jul 17, 2002 at 08:11:50AM +0200, G?czi Szabolcs wrote:
> So after I set up my iproute2 (ip rule add, ip route) my servers answer from
> subnet, BUT the client from subnet can't reach the linuxbox's public
> interface (217.65.110.146) and about this problem, they can't see the
> webpage on the linux box. The internal ip address is available from subnet,
> but the leased line's public interface cannot be reached.
I'm very busy with powerdns now, but on a guess, turn off the reverse path
filter and see if that helps.
Otherwise, tcpdump on ALL interfaces individually and see what happens. Go
beyond "can't reach".
Regards,
bert
--
http://www.PowerDNS.com Versatile DNS Software & Services
http://www.tk the dot in .tk
http://lartc.org Linux Advanced Routing & Traffic Control HOWTO
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2002-07-17 11:25 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-07-12 20:55 [LARTC] Re: 3 interfaces in one linux box bert hubert
2002-07-17 6:11 ` Géczi Szabolcs
2002-07-17 11:25 ` bert hubert
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.