[prev in list] [next in list] [prev in thread] [next in thread] 

List:       cipe
Subject:    Re: masquerading (NAT) through a cipe connection
From:       Manuela Guandalini <guandam () gcs-mbh ! de>
Date:       2001-01-12 9:35:49
[Download RAW message or body]



Stefan Froehlich wrote:

> Hi,
> 
>> It appears that packets routed through a cipe connection cannot be
>> masqueraded, like they can through a ppp connection.  In other words,
>> a computer with a cipe connection to the internet cannot perform
>> masquerading for other hosts on the local subnet over the cipe link.
> 
> 
> *gnarf*
> 
> I've been spending about 3 days time on this issue and finally got
> stuck exactly at this point. Merde.
> 
>> Just thought you might like to know...
> 
>  
> Well, at least, I am not alone. If there _is_ a solution for CIPE,
> 2.4.x and SNAT, please let me know...
> 
> Bye,
>   Stefan
> 
I've been working 4 months to figure out, how to go throu a firewall 
with cipe.
It works now with

ipchains -I forward -s foreign.internal.net.ip/24 -d 0.0.0.0/0 -j fw_masq

some machines need a little different variation:
ipchains -I forward -s foreign.internal.net.ip/24 -d 0.0.0.0/0 -j MASQ

It's perhaps not that secure, but it works.

Does this help u too?
hope so.

Bye.
Manu.


--
Message sent by the cipe-l@inka.de mailing list.
Unsubscribe: mail majordomo@inka.de, "unsubscribe cipe-l" in body
Other commands available with "help" in body to the same address.
CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic