Re: IP Masquerade over IP Alias

David Ford (david@kalifornia.com)
Sun, 15 Aug 1999 13:12:37 -0700


Alexandre Hautequest wrote:

> This is my situation. I have the portfw working, all http packs (for
> example) that go to 200.xxx.xxx.15 goes to my 172.18.xxx.xxx machine.
> But i cannot do the reverse with the packs. I run the ipchains masq
> rule, using the virtual adapter (eth4:3, for exemple), and close all
> doors in the real adapter (eth4). The packs don't go back. Opening the
> firewall ports, and using a packet sniffer besides the fw and the
> router, i saw all packs outgoing with the ip number of my real adapter,
> not with the virtual one.

It's a 'feature' to use the primary IP of an interface unless you specify
otherwise. Obtain the iproute2 package and use the tool 'ip' inside it.

for example:

ip route add 207.213.15.129 via 216.32.34.1 src 216.32.34.187 dev eth0 mtu
1500

specifies the destination, the gateway, and the source IP to use.

ip is the latest and greatest tools for you. it can only be compared to
ifconfig/route in the likeness of a ball peen hammer to a laser chiselling
tool.

ip is good. waste no time getting it. the url for it and some sparse
examples relating to VPNs is available at http://stuph.org/

-d

--
 This is Linux Country. On a quiet night, you can hear Windows NT reboot!
  Do you remember how to -think- ? Do you remember how to experiment? Linux
__ is an operating system that brings back the fun and adventure in computing.
\/  for linux-kernel: please read linux/Documentation/* before posting problems

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/