I have tried to unsubscribe myself 10 times, both by replying to the 
auto address as well as by emailing the human./ No reuslt, I still get 
this stuff.

Please, can I be unsubscribed?

Mike

On Wed, 27 Nov 2002, Rigler, S C (Steve) 
wrote:

> That's correct.  Basically, it looks like:
> 
> VPN Client --> (eth0) RH Machine (eth1) --> Internet --> Extranet Switch
> 
> I didn't put anything special into my rules to enable this.  Aside from the rules I 
>have setup for paranoia, misc port-forwarding, and other traffic, I believe the 
>affecting rules are:
> 
> -A POSTROUTING -o eth1 -j MASQUERADE
> -A FORWARD -s 192.168.10.0/24 -o eth1 -j ACCEPT
> 
> -Steve
> 
> -----Original Message-----
> From: Simpson, Doug [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, November 27, 2002 12:53 PM
> To: '[EMAIL PROTECTED]'
> Subject: RE: VPN masq
> 
> 
> The VPN client is part of your three node network, yes?  It is VPNing to
> another network?
> Thanks,
> Doug
> 
> -----Original Message-----
> From: Rigler, S C (Steve) [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, November 27, 2002 12:40 PM
> To: [EMAIL PROTECTED]
> Subject: RE: VPN masq
> 
> 
> No.
> 
> The redhat box is dual homed, and is firewalling a small (3 node) network.
> The VPN client is a W2K machine running the Nortel EAC client.
> 
> -Steve
> 
> -----Original Message-----
> From: Simpson, Doug [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, November 27, 2002 10:43 AM
> To: '[EMAIL PROTECTED]'
> Subject: RE: VPN masq
> 
> 
> Steve,
> Do you have a roadwarrior setup?
> Doug
> 
> -----Original Message-----
> From: Rigler, S C (Steve) [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, November 27, 2002 8:52 AM
> To: [EMAIL PROTECTED]
> Subject: RE: VPN masq
> 
> 
> I've been doing this successfully since RH 7.1 using iptables and no
> patches.  AFAIK, there is no patch available to do this with ipchains on 2.4
> kernel.  If I remember correctly, the patch only applied to 2.2 kernels
> using ipchains.
> 
> I'm not sure of the limitations of iptables and VPN traffic since I only
> need one connection from one ip to one VPN gateway.  When I first started
> setting this up, the documentation for iptables was fairly sparse, but I
> remember something about ipchains only being able to masq one connection at
> a time.
> 
> -Steve
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, November 27, 2002 8:46 AM
> To: [EMAIL PROTECTED]
> Subject: VPN masq
> 
> 
> I'm running Red HAT 7.3 (2.4.18-18.7.x) as gateway between internal net and
> Internet.
> I use NAT masq on my firewall, and I want to masq also the VPN traffic.
> 
> My question is, do I have to patch kernel (2.4.18-18.7.x) to masq VPN
> traffic?
> 
> 
> Regards Bruma
> 
> 
> -------------------
> http://www.email.si
> 
> 
> 
> 



-- 
redhat-list mailing list
unsubscribe mailto:[EMAIL PROTECTED]?subject=unsubscribe
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to