Steven Kerr wrote:
>
> I just need a pointer with IP Masq/IP Chains as I am confused
> regarding when these tools would be used.
...snip....
As I understand it, IP Masquerading is what is being done and IPChains
is the latest variation of a common program to do this. Before
IPChains, people used ipfwadm.
IPMasquerading basically takes a private IP:Port combo and puts it
into the outside world as a public IP:port combo.
You can then apply filtering to select which packets can enter/leave
your private network.
The configuration of the box doing the filtering with firewall type
security is usual so that other people can not fiddle/bypass the
filtering. That is where the firewall part comes in.
If you want stuff to work from outside, I understand you need to
provide a redirection service as well. E.G. MY www requests from
inside will go out, but www to woa.com.au from outside stop if I take
down my redirector (tcpgate, redir?, etc). This may have changed in IP
Chains
IP Chains is a application that does some or all of this.
You might also want to look at NAT (Network Address Translator), which
I believe is in beta at present.
>
> So if that is the case, what kernel parameters would need to be set to
> masquarade a internal (private) LAN onto the internet via a Linux
> Server.
I think this has been taken out of the kernel and put into settings
(but I'm RH based)
Look at /etc/sysconfig and below.
--
Terry Collins {:-)}}} Ph(02) 4627 2186 Fax(02) 4628 7861
email: [EMAIL PROTECTED] www: http://www.woa.com.au
or [EMAIL PROTECTED]
WOA Computer Services <lan/wan, linux/unix, novell>
snail: PO Box 1047, Campbelltown, NSW 2560.
"People without trees are like fish without clean water"
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text