From: Andrew Beverley <andy@andybev.com>
To: Guido Anzuoni <ganzuoni@gmail.com>
Cc: netfilter@vger.kernel.org
Subject: Re: Hanging outgoing connections while incoming are OK
Date: Wed, 01 Feb 2012 18:58:29 +0000 [thread overview]
Message-ID: <1328122709.1891.11.camel@andy-laptop> (raw)
In-Reply-To: <CACP6TAghHWG2zHfGkPuac2o-qZbuwQHXqddyhUGx3Lwvuch5SA@mail.gmail.com>
On Wed, 2012-02-01 at 16:40 +0100, Guido Anzuoni wrote:
> On Tue, Jan 31, 2012 at 6:37 PM, Andrew Beverley <andy@andybev.com> wrote:
> > On Sat, 2012-01-28 at 09:39 +0100, Guido Anzuoni wrote:
> > ...
> >> fw default gateway: 10.254.254.2
> >> fw eth0: 10.254.254.1, PUB_IP_OUTGOING, PUB_IP_OUTGOING
> > ...
> >> My doubt is about eth0 configuration where I bind multiple addresses,
> >> an internal one and all the public assigned by the ISP.
> >> Is it a correct setup ?
> >
> > Unless I'm misunderstanding something, this does seem like a strange set
> > up. Why not just have the one IP address on eth0? Do the Cisco routers
> > also have an external IP address? Are these 2 completely independent WAN
> > links? If so, how is traffic shared between them?
> >
> > Sorry for all the questions, but I'm not entirely understanding your set
> > up and what you are trying to achieve.
[please don't top-post]
> The intended setup was
> fw eth0: 10.254.254.1, PUB_IP_INCOMING, PUB_IP_OUTGOING
>
> I have used 1 public ip for incoming connections and 1 ip to
> "masquerade" outgoing ones.
> I don't know if it is necessary to bind public ip to some NIC in order
> to let netfilter NAT work properly.
I'm still confused as to what you are trying to achieve with this set
up, and why you have several IP addresses eth0. I would suggest that
this is the cause of your problems.
> It seems like some packets start going round and round before arriving
> to destination.
Which would explain why you are seeing this.
Why not just have one public IP address on eth0 only? And then use that
for incoming and outgoing connections, at least until you've got it
working?
Something like:
[Internal
interfaces] __________
--------------| |eth0
| Linux |(PUB_IP_INCOMING only)
--------------| Box |------------------------->ISP Cisco router
| | ^
--------------|__________| |
|
SNAT here to PUB_IP_INCOMING
Andy
next prev parent reply other threads:[~2012-02-01 18:58 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-01-28 8:39 Hanging outgoing connections while incoming are OK Guido Anzuoni
2012-01-31 17:37 ` Andrew Beverley
2012-02-01 15:40 ` Guido Anzuoni
2012-02-01 18:58 ` Andrew Beverley [this message]
2012-02-02 7:48 ` Guido Anzuoni
2012-02-04 23:27 ` Andrew Beverley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1328122709.1891.11.camel@andy-laptop \
--to=andy@andybev.com \
--cc=ganzuoni@gmail.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox