Linux Advanced Routing and Traffic Control list
 help / color / mirror / Atom feed
From: Dan B db@cyclonehq.dnsalias.net
To: lartc@vger.kernel.org
Subject: Preventing ICMP Redirects?   (was: Re: [LARTC] HTTP only
Date: Thu, 15 Feb 2001 04:44:30 +0000	[thread overview]
Message-ID: <marc-lartc-98373940417020@msgid-missing> (raw)
In-Reply-To: <marc-lartc-98373940417007@msgid-missing>

<PRE>At 02:36 AM 2/11/2001 -0200, Rogerio Brito wrote:
&gt;<i>On Feb 10 2001, bert hubert wrote:
</I>&gt;<i> &gt; You can, I think, but you need to be very sure that your NAT machine
</I>&gt;<i> &gt; isn't sending out any ICMP Redirects.
</I>&gt;<i>
</I>&gt;<i>         I've been bitten by these ICMP Redirects once. Is there any
</I>&gt;<i>         way to prevent them from being sent out? Perhaps doing some
</I>&gt;<i>         packet filtering of the ICMP Redirects? Even if this works,
</I>&gt;<i>         this sure sounds like a dirty solution... :-(
</I>&gt;<i>
</I>&gt;<i>         In that occasion, I was trying to set up a masquerading box
</I>&gt;<i>         with only one NIC and two IP addresses (the Internet-valid one
</I>&gt;<i>         and the private one), hooking everything in a single hub and
</I>&gt;<i>         routing accordingly.
</I>&gt;<i>
</I>&gt;<i>         I don't remember the details (since this was many months ago),
</I>&gt;<i>         but the only solution that I could make work was to buy
</I>&gt;<i>         another NIC for the masquerading box and put one IP in each
</I>&gt;<i>         NIC, doing everything as usual. :-(
</I>&gt;<i>
</I>&gt;<i>         As I don't remember more details of the situation, I'm just
</I>&gt;<i>         hoping that this description rings a bell for someone. Any
</I>&gt;<i>         explanation of how to make this setup with just one NIC or
</I>&gt;<i>         comments on why this shouldn't be done are immensely
</I>&gt;<i>         appreciated.
</I>
Even when you correctly aliased your single NIC to act like two interfaces?

eth0:0  routable ip / external (seperate) subnet
eth1:1 local ip / local subnet

I've done what you described using aliasing a couple of times and I never 
got bit by ICMP redirects (like I did this last time).

Now I kind of wish I would have fixed the ICMP redirect problem instead of 
just changing subnets.  :-)

Dan Browning, Cyclone Computer Systems, <A HREF="mailto:danb@cyclonecomputers.com">danb@cyclonecomputers.com</A>



</PRE>

      reply	other threads:[~2001-02-15  4:44 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-02-11  4:36 Preventing ICMP Redirects? (was: Re: [LARTC] HTTP only works on second try from doublely NAT'ed wi Rogerio
2001-02-15  4:44 ` Dan [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=marc-lartc-98373940417020@msgid-missing \
    --to=lartc@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox