Re: firewall problem

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 3/14/06, Ethy H. Brito <ethy.brito@xxxxxxxxxxxx> wrote:
> On Tue, 14 Mar 2006 14:00:23 +0200
> "Erez D" <erez0001@xxxxxxxxx> wrote:
>
> > well. i ment the ip i got from my isp is aaa.aaa.aaa.aaa, not the
> > local net one, sorry
> >
> > i do not use MASQ. as this did not function well before, and the faq
> > said to preffer SNAT
>
> Would point me this FAQ?
> AFAIK SNAT is to be used on fixed IP and MASQUERADE on dynamic (like ppp's) IP's.
> I woulb like to know if my knowleage is wrong.

i read this faq long time ago so i can not supply a link
all my ips are static (internal and external).

>
> > i have 2 outgoing internet  connections, one via pptp (ppp0), one via
> > router (eth1)
> > i also got a local network - eth0
> >
> > eth1 is 10.0.0.2 connectod to a router which is 10.0.0.1
>
> This one must be NAT'ed somewhere downstream by you ISP.
the router on 10.0.0.1 does the nat
>
> > ppp0 is aaa.aaa.aaa.aaa ptp to ccc.ccc.ccc.ccc
> > eth0 is 192.168.0.254/24
>
> Note that your streams are going out using 192.168.0.254 as source IP and not
> the IPs of your internal machines. Therefore NAT is working.

this is my fault, i copy and pasted different lines
the original tcpdump output was:

IP 192.168.0.20.5070 > bbb.bbb.bbb.bbb.5060

>
> And also, outgoing via two routers is a tricky thing to put to work.
> There are some docs aronud about this subject.

yeah, i tried them all, including patching the kernel with some
suggested patches, but never got load balancing to work, so gave it up
long time ago.

at the end, i put default route on one interface, and selected
manually what will go via the other via fwmark and/or source routing
and/or standard routing (i.e. dest routing)

thanks,
erez.

>
> Regards
>
> --
>
> Ethy H. Brito         /"\
> InterNexo Ltda.       \ /  CAMPANHA DA FITA ASCII - CONTRA MAIL HTML
> +55 (12) 3941-6860     X   ASCII RIBBON CAMPAIGN - AGAINST HTML MAIL
> S.J.Campos - Brasil   / \
>
_______________________________________________
LARTC mailing list
LARTC@xxxxxxxxxxxxxxx
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc


[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux