Steven Kerr wrote:
> 
> I just need a pointer with IP Masq/IP Chains as I am confused
> regarding when these tools would be used.
...snip....

As I understand it, IP Masquerading is what is being done and IPChains
is the latest variation of a common program to do this. Before
IPChains, people used ipfwadm.  

IPMasquerading basically takes a private IP:Port combo and puts it
into the outside world as a public IP:port combo.

You can then apply filtering to select which packets can enter/leave
your private network.

The configuration of the box doing the filtering with firewall type
security is usual so that other people can not fiddle/bypass the
filtering. That is where the firewall part comes in.

If you want stuff to work from outside, I understand you need to
provide a redirection service as well. E.G. MY www requests from
inside will go out, but www to woa.com.au from outside stop if I take
down my redirector (tcpgate, redir?, etc). This may have changed in IP
Chains

IP Chains is a application that does some or all of this.

You might also want to look at NAT (Network Address Translator), which
I believe is in beta at present.

> 
> So if that is the case, what kernel parameters would need to be set to
> masquarade a internal (private) LAN onto the internet via a Linux
> Server.

I think this has been taken out of the kernel and put into settings
(but I'm RH based)
Look at /etc/sysconfig and below.

--
   Terry Collins {:-)}}} Ph(02) 4627 2186 Fax(02) 4628 7861  
   email: [EMAIL PROTECTED]  www: http://www.woa.com.au  
       or [EMAIL PROTECTED] 
   WOA Computer Services <lan/wan, linux/unix, novell>
   snail:  PO Box 1047, Campbelltown, NSW 2560.

 "People without trees are like fish without clean water"
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to