Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Rimas" <rmocius@auste.elnet.lt>
To: netfilter@lists.netfilter.org
Cc: Sean Oh <oh@storageone.co.kr>
Subject: Re: IP MASQ and IPROUTE2?
Date: Tue, 15 Oct 2002 13:11:58 +0100	[thread overview]
Message-ID: <01d201c27444$113613b0$6e69690a@rimas> (raw)
In-Reply-To: 001101c273f5$fc2c5220$c300a8c0@COMPAQ

Sean,

You need to both eth cards.
Like this:

iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_1 -j MASQUERADE
iptables -t nat -A POSTROUTING -o $EXTERNAL_INTERFACE_2 -j MASQUERADE

Rimas




----- Original Message -----
From: "Sean Oh" <oh@storageone.co.kr>
To: <netfilter@lists.netfilter.org>
Sent: Tuesday, October 15, 2002 3:53 AM
Subject: IP MASQ and IPROUTE2?


> Hi
>
> I am having a little problem with IP MASQ and IPROUTE2.
> I am using RedHat 7.3 with IPTABLES.
>
> I have a linux gateway server with 3 NICs.
> The environment is as follows:
>
>
> Local Network      +------------+ eth1(218.x.x.20) --> ISP1
> (192.168.0.x) --- | Linux Server |--------
>                 eth0   |                    |
>       192.168.0.1  |                    |--------
>                          +-------------+ eth2(211.x.x.155) -->ISP2
>
>
> The eth1 and eth2 are the links to internet. I  have 2 providers to
Internet
> and I would like to use eth2 as the default route to internet from Local
> Network(192.168.0.x) and eth1 as for the servers(DNS, mail, web) that
people from external Internet
> to access. The reason behind that is that provider ISP2 are not
> allowing me to run servers on that link, so I had to setup another link
for
> servers(eth1).
>
> The IP masqurading is used and ip forwarding is turned on.
>
> echo 1 > /proc/sys/net/ipv4/ip_forward
>
> /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155 table SI
> /sbin/ip route add default via 211.x.x.129 table SI
> /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20 table KT
> /sbin/ip route add default via 218.x.x.1 table KT
>
> /sbin/ip route add 211.x.x.128 dev eth2 src 211.x.x.155
> /sbin/ip route add 218.x.x.0 dev eth1 src 218.x.x.20
>
> /sbin/ip route add default via 211.x.x.129
>
> /sbin/ip rule add from 211.x.x.155 table SI
> /sbin/ip rule add from 218.x.x.20 table KT
>
> /sbin/iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
> /sbin/iptables -P FORWARD ACCEPT
> /sbin/iptables -P INPUT ACCEPT
> /sbin/iptables -P OUTPUT ACCEPT
>
>
> [root@www root]# ip route show
> 211.x.x.128 dev eth2  scope link  src 211.x.x.155
> 218.x.x.0 dev eth1  scope link  src 218.x.x.20
> 211.x.x.128/25 dev eth2  scope link
> 192.168.0.0/24 dev eth0  scope link
> 218.x.x.0/24 dev eth1  scope link
> 127.0.0.0/8 dev lo  scope link
> default via 211.x.x.129 dev eth2
>
>
> it works fine( 192.168.0.x can access the internet by masquerading via
eth2 and external internet can access the eth1 and eth2).
> But the problem is that the hosts in the local network (192.168.0.x) can
not access 211.x.x.155(eth2) and 218.x.x.20(eth1), even though ip forwarding
is turned on. It can only access 192.168.0.1
>
> Could someone please sugguested me the solutions?
>
> Thanks in advance.
>
>




  reply	other threads:[~2002-10-15 12:11 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-15  2:53 IP MASQ and IPROUTE2? Sean Oh
2002-10-15 12:11 ` Rimas [this message]
2002-10-15 14:59   ` Sean Oh
2002-10-15 15:52     ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='01d201c27444$113613b0$6e69690a@rimas' \
    --to=rmocius@auste.elnet.lt \
    --cc=netfilter@lists.netfilter.org \
    --cc=oh@storageone.co.kr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox