Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Sean Oh" <oh@storageone.co.kr>
To: Rimas <rmocius@auste.elnet.lt>, netfilter@lists.netfilter.org
Subject: Re: IP MASQ and IPROUTE2?
Date: Tue, 15 Oct 2002 23:59:31 +0900	[thread overview]
Message-ID: <015401c2745b$777be750$f800a8c0@COMPAQ> (raw)
In-Reply-To: 01d201c27444$113613b0$6e69690a@rimas

Rimas,

I tried what you said, but I stil can not access the server using ip addresses of eth1 and eth2.

----- Original Message ----- 
From: "Rimas" <rmocius@auste.elnet.lt>
To: <netfilter@lists.netfilter.org>
Cc: "Sean Oh" <oh@storageone.co.kr>
Sent: Tuesday, October 15, 2002 9:11 PM
Subject: Re: IP MASQ and IPROUTE2?


> Sean,
> 
> You need to both eth cards.
> Like this:
> 
> iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_1 -j MASQUERADE
> iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_2 -j MASQUERADE
> 
> Rimas
> 
> 
> 
> 
> ----- Original Message -----
> From: "Sean Oh" <oh@storageone.co.kr>
> To: <netfilter@lists.netfilter.org>
> Sent: Tuesday, October 15, 2002 3:53 AM
> Subject: IP MASQ and IPROUTE2?
> 
> 
> > Hi
> >
> > I am having a little problem with IP MASQ and IPROUTE2.
> > I am using RedHat 7.3 with IPTABLES.
> >
> > I have a linux gateway server with 3 NICs.
> > The environment is as follows:
> >
> >
> > Local Network      +------------+ eth1(218.x.x.20) --> ISP1
> > (192.168.0.x) --- | Linux Server |--------
> >                 eth0   |                    |
> >       192.168.0.1  |                    |--------
> >                          +-------------+ eth2(211.x.x.155) -->ISP2
> >
> >
> > The eth1 and eth2 are the links to internet. I  have 2 providers to
> Internet
> > and I would like to use eth2 as the default route to internet from Local
> > Network(192.168.0.x) and eth1 as for the servers(DNS, mail, web) that
> people from external Internet
> > to access. The reason behind that is that provider ISP2 are not
> > allowing me to run servers on that link, so I had to setup another link
> for
> > servers(eth1).
> >
> > The IP masqurading is used and ip forwarding is turned on.
> >
> > echo 1 > /proc/sys/net/ipv4/ip_forward
> >
> > /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155 table SI
> > /sbin/ip route add default via 211.x.x.129 table SI
> > /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20 table KT
> > /sbin/ip route add default via 218.x.x.1 table KT
> >
> > /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155
> > /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20
> >
> > /sbin/ip route add default via 211.x.x.129
> >
> > /sbin/ip rule add from 211.x.x.155 table SI
> > /sbin/ip rule add from 218.x.x.20 table KT
> >
> > /sbin/iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
> > /sbin/iptables -P FORWARD ACCEPT
> > /sbin/iptables -P INPUT ACCEPT
> > /sbin/iptables -P OUTPUT ACCEPT
> >
> >
> > [root@www root]# ip route show
> > 211.x.x.128 dev eth2  scope link  src 211.x.x.155
> > 218.x.x.0 dev eth1  scope link  src 218.x.x.20
> > 211.x.x.128/25 dev eth2  scope link
> > 192.168.0.0/24 dev eth0  scope link
> > 218.x.x.0/24 dev eth1  scope link
> > 127.0.0.0/8 dev lo  scope link
> > default via 211.x.x.129 dev eth2
> >
> >
> > it works fine( 192.168.0.x can access the internet by masquerading via
> eth2 and external internet can access the eth1 and eth2).
> > But the problem is that the hosts in the local network (192.168.0.x) can
> not access 211.x.x.155(eth2) and 218.x.x.20(eth1), even though ip forwarding
> is turned on. It can only access 192.168.0.1
> >
> > Could someone please sugguested me the solutions?
> >
> > Thanks in advance.
> >
> >
> 
> 
> 
> 

  reply	other threads:[~2002-10-15 14:59 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-15  2:53 IP MASQ and IPROUTE2? Sean Oh
2002-10-15 12:11 ` Rimas
2002-10-15 14:59   ` Sean Oh [this message]
2002-10-15 15:52     ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='015401c2745b$777be750$f800a8c0@COMPAQ' \
    --to=oh@storageone.co.kr \
    --cc=netfilter@lists.netfilter.org \
    --cc=rmocius@auste.elnet.lt \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox