From: "Sean Oh" <oh@storageone.co.kr>
To: Rimas <rmocius@auste.elnet.lt>, netfilter@lists.netfilter.org
Subject: Re: IP MASQ and IPROUTE2?
Date: Tue, 15 Oct 2002 23:59:31 +0900 [thread overview]
Message-ID: <015401c2745b$777be750$f800a8c0@COMPAQ> (raw)
In-Reply-To: 01d201c27444$113613b0$6e69690a@rimas
Rimas,
I tried what you said, but I stil can not access the server using ip addresses of eth1 and eth2.
----- Original Message -----
From: "Rimas" <rmocius@auste.elnet.lt>
To: <netfilter@lists.netfilter.org>
Cc: "Sean Oh" <oh@storageone.co.kr>
Sent: Tuesday, October 15, 2002 9:11 PM
Subject: Re: IP MASQ and IPROUTE2?
> Sean,
>
> You need to both eth cards.
> Like this:
>
> iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_1 -j MASQUERADE
> iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_2 -j MASQUERADE
>
> Rimas
>
>
>
>
> ----- Original Message -----
> From: "Sean Oh" <oh@storageone.co.kr>
> To: <netfilter@lists.netfilter.org>
> Sent: Tuesday, October 15, 2002 3:53 AM
> Subject: IP MASQ and IPROUTE2?
>
>
> > Hi
> >
> > I am having a little problem with IP MASQ and IPROUTE2.
> > I am using RedHat 7.3 with IPTABLES.
> >
> > I have a linux gateway server with 3 NICs.
> > The environment is as follows:
> >
> >
> > Local Network +------------+ eth1(218.x.x.20) --> ISP1
> > (192.168.0.x) --- | Linux Server |--------
> > eth0 | |
> > 192.168.0.1 | |--------
> > +-------------+ eth2(211.x.x.155) -->ISP2
> >
> >
> > The eth1 and eth2 are the links to internet. I have 2 providers to
> Internet
> > and I would like to use eth2 as the default route to internet from Local
> > Network(192.168.0.x) and eth1 as for the servers(DNS, mail, web) that
> people from external Internet
> > to access. The reason behind that is that provider ISP2 are not
> > allowing me to run servers on that link, so I had to setup another link
> for
> > servers(eth1).
> >
> > The IP masqurading is used and ip forwarding is turned on.
> >
> > echo 1 > /proc/sys/net/ipv4/ip_forward
> >
> > /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155 table SI
> > /sbin/ip route add default via 211.x.x.129 table SI
> > /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20 table KT
> > /sbin/ip route add default via 218.x.x.1 table KT
> >
> > /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155
> > /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20
> >
> > /sbin/ip route add default via 211.x.x.129
> >
> > /sbin/ip rule add from 211.x.x.155 table SI
> > /sbin/ip rule add from 218.x.x.20 table KT
> >
> > /sbin/iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
> > /sbin/iptables -P FORWARD ACCEPT
> > /sbin/iptables -P INPUT ACCEPT
> > /sbin/iptables -P OUTPUT ACCEPT
> >
> >
> > [root@www root]# ip route show
> > 211.x.x.128 dev eth2 scope link src 211.x.x.155
> > 218.x.x.0 dev eth1 scope link src 218.x.x.20
> > 211.x.x.128/25 dev eth2 scope link
> > 192.168.0.0/24 dev eth0 scope link
> > 218.x.x.0/24 dev eth1 scope link
> > 127.0.0.0/8 dev lo scope link
> > default via 211.x.x.129 dev eth2
> >
> >
> > it works fine( 192.168.0.x can access the internet by masquerading via
> eth2 and external internet can access the eth1 and eth2).
> > But the problem is that the hosts in the local network (192.168.0.x) can
> not access 211.x.x.155(eth2) and 218.x.x.20(eth1), even though ip forwarding
> is turned on. It can only access 192.168.0.1
> >
> > Could someone please sugguested me the solutions?
> >
> > Thanks in advance.
> >
> >
>
>
>
>
next prev parent reply other threads:[~2002-10-15 14:59 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-10-15 2:53 IP MASQ and IPROUTE2? Sean Oh
2002-10-15 12:11 ` Rimas
2002-10-15 14:59 ` Sean Oh [this message]
2002-10-15 15:52 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='015401c2745b$777be750$f800a8c0@COMPAQ' \
--to=oh@storageone.co.kr \
--cc=netfilter@lists.netfilter.org \
--cc=rmocius@auste.elnet.lt \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox