Linux Netfilter discussions
 help / color / mirror / Atom feed
* Re: Dual WAN set-up
@ 2012-01-16 21:43 Dimitri Yioulos
  0 siblings, 0 replies; 19+ messages in thread
From: Dimitri Yioulos @ 2012-01-16 21:43 UTC (permalink / raw)
  To: netfilter@vger.kernel.org

On Monday 16 January 2012 3:28:14 pm you wrote:
> On Mon, 16 Jan 2012 08:56:23 -0600, Dimitri Yioulos 
<dyioulos@onpointfc.com> wrote:
> > Before I commit this new set-up, I'd like to post the
> > ste-by-step instructions I wrote up for your kind review:
>
> I don't quite understand your network configuration, but the
> ideas we provided on split-access to uplinks should adaptable
> to any situation.
>
> > Under this set-up, don't I need to add POSTROUTING AND
> > FORWARDING rules?  Sorry for my stupidity, but I set the
> > original up a long time ago, and certainly don't know all
> > there is to know.  Your continued patience and support are
> > greatly appreciated.
>
> The PREROUTING chain of the mangle table will handle the
> marking of new connection packets as well as recovery of the
> connection mark to the packet mark.  There should be no other
> iptables stuff required to mark the packets, and "ip rule add
> fwmark..." will handle sending the marked packets to the right
> routing table.
>
> I think you are doing SNAT, which uses POSTROUTING chain.  You
> you will want to keep that.
>
> Others here are much more knowledgeable and may have more
> comments. --
> Lloyd

Thanks, Lloyd.  Sorry if I'm being a pita.  I think what I'll do 
is follow your instructions, but liven up a test server first 
(doh :-)  ).  Of course, if that works, the rest is cake.  If it 
doesn't, hopefully I'll have some error messages/more information 
to post back so that we can do some troubleshooting.  Sound 
reasonable?

Dimitri

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.


^ permalink raw reply	[flat|nested] 19+ messages in thread
* Dual WAN set-up
@ 2012-01-12 21:51 Dimitri Yioulos
  2012-01-12 22:28 ` Andrew Beverley
  2012-01-12 23:08 ` Lloyd Standish
  0 siblings, 2 replies; 19+ messages in thread
From: Dimitri Yioulos @ 2012-01-12 21:51 UTC (permalink / raw)
  To: netfilter

Hi, folks.

Please bear with me.  I may have asked something similar in the 
way-back, but am going to ask again, because I really need to get 
this set up, have absolutely no idea how, and am pertrified at 
the prospect:

I currently have an iptables/Netfilter firewall router configured 
thusly:

                               WAN
                                  |
 (192.168.x.x) LAN --  fw -- DMZ (10.x.x.x)

OK, pretty basic.  And, it has worked well for a long time.

Now, I need to add a second WAN (provided by a second provider).  
I need it to serve specific boxes in the DMZ, both inbound and 
outbound.  Currently, all boxes in the DMZ are served by the 
single WAN connection.  I'm not sure what other information I 
need to provide you, but I'm hoping you all can help with very 
specific instructions or a very detailed how-to so I can get this 
accomplished.  And, of course, I need to get this done yesterday.

Many thanks.

Dimitri

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.


^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2012-01-16 21:43 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-01-16 21:43 Dual WAN set-up Dimitri Yioulos
  -- strict thread matches above, loose matches on Subject: below --
2012-01-12 21:51 Dimitri Yioulos
2012-01-12 22:28 ` Andrew Beverley
2012-01-12 22:48   ` Dimitri Yioulos
2012-01-13  7:18     ` Andrew Beverley
2012-01-12 23:08 ` Lloyd Standish
2012-01-12 23:12   ` Lloyd Standish
2012-01-12 23:22     ` Dimitri Yioulos
2012-01-12 23:19   ` Dimitri Yioulos
2012-01-13  0:52   ` Lloyd Standish
2012-01-13  7:25   ` Andrew Beverley
2012-01-13 11:47     ` Dimitri Yioulos
2012-01-13 14:17     ` Lloyd Standish
2012-01-13 15:17       ` Dimitri Yioulos
2012-01-13 15:22         ` Dimitri Yioulos
2012-01-14  2:27           ` Lloyd Standish
     [not found]           ` <201201160956.23955.dyioulos@onpointfc.com>
2012-01-16 20:28             ` Lloyd Standish
2012-01-13 20:00         ` Lloyd Standish
2012-01-13 20:04           ` Dimitri Yioulos

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox