From: "Rimas" <rmocius@auste.elnet.lt>
To: netfilter@lists.netfilter.org
Cc: Sean Oh <oh@storageone.co.kr>
Subject: Re: IP MASQ and IPROUTE2?
Date: Tue, 15 Oct 2002 13:11:58 +0100 [thread overview]
Message-ID: <01d201c27444$113613b0$6e69690a@rimas> (raw)
In-Reply-To: 001101c273f5$fc2c5220$c300a8c0@COMPAQ
Sean,
You need to both eth cards.
Like this:
iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_1 -j MASQUERADE
iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_2 -j MASQUERADE
Rimas
----- Original Message -----
From: "Sean Oh" <oh@storageone.co.kr>
To: <netfilter@lists.netfilter.org>
Sent: Tuesday, October 15, 2002 3:53 AM
Subject: IP MASQ and IPROUTE2?
> Hi
>
> I am having a little problem with IP MASQ and IPROUTE2.
> I am using RedHat 7.3 with IPTABLES.
>
> I have a linux gateway server with 3 NICs.
> The environment is as follows:
>
>
> Local Network +------------+ eth1(218.x.x.20) --> ISP1
> (192.168.0.x) --- | Linux Server |--------
> eth0 | |
> 192.168.0.1 | |--------
> +-------------+ eth2(211.x.x.155) -->ISP2
>
>
> The eth1 and eth2 are the links to internet. I have 2 providers to
Internet
> and I would like to use eth2 as the default route to internet from Local
> Network(192.168.0.x) and eth1 as for the servers(DNS, mail, web) that
people from external Internet
> to access. The reason behind that is that provider ISP2 are not
> allowing me to run servers on that link, so I had to setup another link
for
> servers(eth1).
>
> The IP masqurading is used and ip forwarding is turned on.
>
> echo 1 > /proc/sys/net/ipv4/ip_forward
>
> /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155 table SI
> /sbin/ip route add default via 211.x.x.129 table SI
> /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20 table KT
> /sbin/ip route add default via 218.x.x.1 table KT
>
> /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155
> /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20
>
> /sbin/ip route add default via 211.x.x.129
>
> /sbin/ip rule add from 211.x.x.155 table SI
> /sbin/ip rule add from 218.x.x.20 table KT
>
> /sbin/iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
> /sbin/iptables -P FORWARD ACCEPT
> /sbin/iptables -P INPUT ACCEPT
> /sbin/iptables -P OUTPUT ACCEPT
>
>
> [root@www root]# ip route show
> 211.x.x.128 dev eth2 scope link src 211.x.x.155
> 218.x.x.0 dev eth1 scope link src 218.x.x.20
> 211.x.x.128/25 dev eth2 scope link
> 192.168.0.0/24 dev eth0 scope link
> 218.x.x.0/24 dev eth1 scope link
> 127.0.0.0/8 dev lo scope link
> default via 211.x.x.129 dev eth2
>
>
> it works fine( 192.168.0.x can access the internet by masquerading via
eth2 and external internet can access the eth1 and eth2).
> But the problem is that the hosts in the local network (192.168.0.x) can
not access 211.x.x.155(eth2) and 218.x.x.20(eth1), even though ip forwarding
is turned on. It can only access 192.168.0.1
>
> Could someone please sugguested me the solutions?
>
> Thanks in advance.
>
>
next prev parent reply other threads:[~2002-10-15 12:11 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-10-15 2:53 IP MASQ and IPROUTE2? Sean Oh
2002-10-15 12:11 ` Rimas [this message]
2002-10-15 14:59 ` Sean Oh
2002-10-15 15:52 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='01d201c27444$113613b0$6e69690a@rimas' \
--to=rmocius@auste.elnet.lt \
--cc=netfilter@lists.netfilter.org \
--cc=oh@storageone.co.kr \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox