From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.samba.org
Subject: Re: can iptables do this?
Date: Thu, 13 Jun 2002 18:25:41 +0100 [thread overview]
Message-ID: <200206131726.SAA08720@slate.rockstone.co.uk> (raw)
In-Reply-To: <Pine.LNX.4.44.0205211422380.4011-100000@space.comunit.de>
On Tuesday 21 May 2002 1:27 pm, Sven Koch wrote:
> On Tue, 21 May 2002, Antony Stone wrote:
> > On Tuesday 21 May 2002 10:47 am, Eduardo GARCIA wrote:
> > > For example my network is 1.2.3.0 and I want that a host with an IP
> > > from any unknown network (i. e. 10.9.8.7) can navigate.
> >
> > No way. You can't create a network which will allow a host with some
> > arbitrary preset IP address (and gateway, and DNS...) to come along an
> > plug into - for two reasons:
>
> You can, at least one commercial device does right that - see
> www.nomadix.com for ther usg (universal subscriber gateway).
>
> It seems to be some kind of "answer to every arp request" combined with
> nat - won't be easy, but it should be doable with iptables and some
> home-grown programs.
I still maintain that this method won't work for all cases (although I could
see that it might cover the majority of IP addresses).
Suppose, for example, that I work for Hewlett-Packard, who have a Class A
network on address 15.0.0.0/255.0.0.0
Then my PC will have an address somewhere in this range (remember we're not
using DHCP here, so I must have a static address), and it will consider all
other addresses in this range as local, not to be routed through a gateway.
Then if I take this machine and plug it into the network described above, and
I assume that it handles all the arp requests very cleverly, it's still going
to allow me to access anything on the Internet except my 'own' local network,
15.0.0.0/255.0.0.0, which is actually quite a likely one for me to want to
contact whilst I'm out and about.....
The reason I think I won't be able to access my 'own' network is because my
machine will expect to find 15.x.y.z servers locally, not through any router,
therefore it's going to look for machines on the local net, not through the
gateway it magically discovers through all this arp nonsense....
Anybody explain where my reasoning falls down so this crazy scheme *can*
actually work ?
Antony.
next prev parent reply other threads:[~2002-06-13 17:25 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <OFE9A4EDE9.418F3246-ONC1256BC0.0035D17B-C1256BC0.0035D196@upc.es>
[not found] ` <200205211157.MAA18294@slate.rockstone.co.uk>
2002-05-21 12:27 ` can iptables do this? Sven Koch
2002-06-13 17:25 ` Antony Stone [this message]
[not found] ` <3CEA8069.EA2F5F84@spamless.genwax.com>
[not found] ` <200205211742.SAA19742@slate.rockstone.co.uk>
2002-05-21 23:48 ` Edu
2004-01-02 17:19 public ip on LAN Amit Pasari
2004-01-02 17:27 ` Fabien LE BLEVEC
2004-01-02 18:30 ` Craig Steadman
2004-01-02 18:46 ` Michael Gale
2004-01-02 19:07 ` Can iptables do this ? Ramoni
2004-01-02 19:19 ` Antony Stone
[not found] <OF48E1B4A6.4F38281F-ONC1256BBF.004241A8-C1256BBF.004241D4@upc.es>
[not found] ` <200205201336.OAA14181@slate.rockstone.co.uk>
2002-05-20 17:05 ` Can iptables do this? eduardg
-- strict thread matches above, loose matches on Subject: below --
2002-05-20 10:23 eduardg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200206131726.SAA08720@slate.rockstone.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox