On 21 May 99, at 17:05, Stephen Mills wrote about
    "Re: [Masq]  Re: exception to the ru":

| For instance : If I want to deny 128.0.100.15 the ability to masquerade for
| browsing the web etc and let the rest of the Class A, 128.0.100/16 allowed
| to, If I do something like :
|...

I see Fuzzy Fox already answered this, but it gives me a chance to 
appologise for posting a bit of mis-information earlier in this 
thread:
 
| > You weren't too specific about what you tried that didn't work.  If
| > it was a Forward or Output rule, it won't work because masquerading
| > has already taken place.

I plead brain fart.  Since the forwarding rules *cause* the 
masquerading, obviously they see the original source address.  It's 
only output rules on the external interface that don't see the 
original internal source addresses.  Doh!

|...

- Fred Viles <mailto:[EMAIL PROTECTED]>




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to