From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?iso-8859-1?B?THVpcyBIZXJu4W4gT3RlZ3Vp?= Subject: Three NICs, three LANs, only one must be MASQued Date: Tue, 16 Mar 2004 10:20:20 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1"; format="flowed" Content-Transfer-Encoding: quoted-printable To: netfilter@lists.netfilter.org Hi, everyone. I decided to write to the list because, frankly, I've been=20 overwhelmed by this problem, and I couldn't find any previously solved=20 similar issue. Here's the scenario: I manage a network with a proxy server (running SQUID and IPTABLES, kernel = 2.4.18-14) which used to have two NICs, both networks attached to those NIC= s=20 with public IP addresses. Recently, we had to put a third NIC in the proxy,= =20 with private reserved (10.0.0.x) addresses. So, we had to masquerade all th= e=20 traffic from the two "internal" networks. Here's the diagram: INTERNET | (public IPs network(A)) | / (corporative LAN)-----(proxy)< \ (private IPs network(B)) So far, so good, but the point is that I need the servers in the (A) networ= k=20 to maintain their IPs, since they're well known in the net. And also we nee= d=20 the hosts in the (B) network to be masqued, since their IPs cannot be route= d=20 over the internet. My questions are: a) Are there any way to masquerade only the (B) network? Currently, I have = a=20 line like this in the *nat section of the /etc/sysconfig/iptables file: -A POSTROUTING -o eth0 -j MASQUERADE b) Is there any better way to do this? ok, I think you'll get it better if I post the iptables script, so here it = goes: Remarks: 163.10.5.75 is the outer interface (eth0), 163.10.7.126 is the NIC= =20 of the "public" inner network, and 10.0.0.1 is the address of the "private"= =20 inner network. # Generated by iptables-save v1.2.6a on Tue Feb 3 11:44:12 2004 *nat :PREROUTING ACCEPT [28330:2376442] :POSTROUTING ACCEPT [2964:192723] :OUTPUT ACCEPT [22208:1482370] -A PREROUTING -d ! 163.10.5.75 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT= =20 --to-ports 3128 #-A PREROUTING -s 163.10.7.114 -i eth1 -p tcp -m tcp -j ACCEPT -A PREROUTING -d ! 163.10.5.75 -i eth2 -p tcp -m tcp --dport 80 -j REDIRECT= =20 --to-ports 3128 -A POSTROUTING -o eth0 -j MASQUERADE COMMIT # Completed on Tue Feb 3 11:44:12 2004 # Generated by iptables-save v1.2.6a on Tue Feb 3 11:44:12 2004 *filter :INPUT ACCEPT [475802:357605367] :FORWARD ACCEPT [14845:1895096] :OUTPUT ACCEPT [1360638:579882577] -A INPUT -i lo -j ACCEPT -A INPUT -i eth1 -j ACCEPT -A INPUT -i eth2 -j ACCEPT -A FORWARD -i eth1 -j ACCEPT -A FORWARD -i eth2 -j ACCEPT COMMIT I forgot to mention that I forward all traffic from the inner interfaces to= =20 port 80 to port 3128 (SQUID) Any suggestions will be very wellcomed Oh, and finally, sorry about my English, I learned by post mail, and I=20 managed to choice the worst time to do this, since the postmans were on=20 strike... ;-) Luis Hern=E1n Otegui Administrador de Red Facultad de Ciencias Exactas UNLP ---------------------------------------------------- GNU-GPL: "May The Source Be With You..." ---------------------------------------------------- _________________________________________________________________ Charla con tus amigos en l=EDnea mediante MSN Messenger:=20 http://messenger.latam.msn.com/