Linux Netfilter discussions
 help / color / mirror / Atom feed
* Unusual routing problem
@ 2003-03-24 18:25 Benjamin Tompkins
  2003-03-24 19:28 ` Kim Jensen
  0 siblings, 1 reply; 6+ messages in thread
From: Benjamin Tompkins @ 2003-03-24 18:25 UTC (permalink / raw)
  To: netfilter

I am attempting to route myself an ip block from my office to my home via a
tunnel. Simple enough. The catch is, I only want the tunnel to be used for
lan destined traffic and incoming connections to my IP block. The lan
destined traffic is easy, the trick apparently is getting the block to be
accessible via the internet, without forcing all traffic to use the tunnel.
A diagram.

eth0  (DHCP) cable modem            eth1  (x.x.x.1/28) LAN
                                              \   /
                                      Linux Machine
                                                |
                                 ppp0 (x.x.x.2/30)

Ok, so what I have so far is as follows.

This takes care of access to the office network.
route add -net x.x.x.1 netmask 255.255.255.240 dev eth1
route add -net x.x.x.0 netmask 255.255.254.0 dev ppp0
route add -host x.x.x.1 dev eth0

Now to use the cable for everything else.
iptables -A POSTROUTING -s x.x.x.1/28 -o eth0 -j MASQUERADE

So now I can access my office lan and vice versa, and everything else gets
masqed out the cable. But I'm having a heck of a time letting the box to
know that stuff requested via ppp0, needs to go out ppp0. I have looked at
using the mangle table making rules for input and forward, but am just
missing something along the way. Any help anyone can offer would be greatly
appreciated. Thanks.



^ permalink raw reply	[flat|nested] 6+ messages in thread
* Unusual routing problem
@ 2003-03-24 18:18 Benjamin Tompkins
  2003-04-01 17:58 ` Matthew G. Marsh
  0 siblings, 1 reply; 6+ messages in thread
From: Benjamin Tompkins @ 2003-03-24 18:18 UTC (permalink / raw)
  To: netfilter

I am attempting to route myself an ip block from my office to my home via a
tunnel. Simple enough. The catch is, I only want the tunnel to be used for
lan destined traffic and incoming connections to my IP block. The lan
destined traffic is easy, the trick apparently is getting the block to be
accessible via the internet, without forcing all traffic to use the tunnel.
A diagram.

eth0  (DHCP) cable modem            eth1  (x.x.x.1/28) LAN
                                              \   /
                                      Linux Machine
                                                |
                                 ppp0 (x.x.x.2/30)

Ok, so what I have so far is as follows.

This takes care of access to the office network.
route add -net x.x.x.1 netmask 255.255.255.240 dev eth1
route add -net x.x.x.0 netmask 255.255.254.0 dev ppp0
route add -host x.x.x.1 dev eth0

Now to use the cable for everything else.
iptables -A POSTROUTING -s x.x.x.1/28 -o eth0 -j MASQUERADE

So now I can access my office lan and vice versa, and everything else gets
masqed out the cable. But I'm having a heck of a time letting the box to
know that stuff requested via ppp0, needs to go out ppp0. I have looked at
using the mangle table making rules for input and forward, but am just
missing something along the way. Any help anyone can offer would be greatly
appreciated. Thanks.

Benji



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-04-01 17:58 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-03-24 18:25 Unusual routing problem Benjamin Tompkins
2003-03-24 19:28 ` Kim Jensen
2003-03-30 19:00   ` Benjamin Tompkins
2003-03-31 16:52     ` Kim Jensen
  -- strict thread matches above, loose matches on Subject: below --
2003-03-24 18:18 Benjamin Tompkins
2003-04-01 17:58 ` Matthew G. Marsh

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox