------=_Part_13090_25923287.1210375991818
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hello,
I'm trying to setup a firewall/gateway/content-filter on a recent internet
link that was installed. I am up against a few difficulties however due to
the nature of my current network config.
For one, this is a supplementary connection to relieve the main business
T1
wan-haul. So routing has to be setup to keep other internal nets over the
wan working (this is easy enough). Current internet traffic heads out over
this link. That traffic needs to be redirected, which is how I've set it
up.
Second issue. Internal addressing is in public address space. Masq seems
to
fail and with out it, packets get lost in the cloud between the uplinks.
So the question is, can I successfully Masq public ip space to make
packets
return on the path they left on? Are there any special config requirements
for this? Or would I have to bite the bullet and re-ip the subnet in
question to private space?
Any other tips would be appreciated as well.
------=_Part_13090_25923287.1210375991818
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hello,<br>
<br>
I'm trying to setup a firewall/gateway/content-filter on a recent
internet link that was installed. I am up against a few difficulties
however due to the nature of my current network config.<br>
<br>
For one, this is a supplementary connection to relieve the main
business T1 wan-haul. So routing has to be setup to keep other internal
nets over the wan working (this is easy enough). Current internet
traffic heads out over this link. That traffic needs to be redirected,
which is how I've set it up.<br>
<br>
Second issue. Internal addressing is in public address space. Masq
seems to fail and with out it, packets get lost in the cloud between
the uplinks.<br>
<br>
So the question is, can I successfully Masq public ip space to make
packets return on the path they left on? Are there any special config
requirements for this? Or would I have to bite the bullet and re-ip the
subnet in question to private space?<br>
<br>
Any other tips would be appreciated as well.<br>
------=_Part_13090_25923287.1210375991818--
--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@[EMAIL PROTECTED]
a subject of "unsubscribe". Trouble? Contact
listmaster@[EMAIL PROTECTED]


|