LinuxQuestions.org
Support LQ: Use code LQCO20 and save 20% on CrossOver Office
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 01-25-2005, 05:49 PM   #1
pe2338
Member
 
Registered: Dec 2002
Location: Bucharest,RO
Distribution: debian etch, sarge and sid
Posts: 407

Rep: Reputation: 30
two ISP and a weird LAN setting / services not visible from outside (routing problem)


Hello all,

I have a weird problem:

I am the admin of the server in my dorms where we have two ISPs.
We have only a server with 4 Ethernet cards (of which 1 is unused).
- one internal
- one pure external on cable link
- one external on a faster, but more restrictive ISP (used also to connect to other dorms)

Services provided by server:
- dchub
- firewall
- web server
- mail server (smtp and imaps)
- ssh, of course


My slow connection has a FQ(sub)DN and is the way I want to receive www connections/mails/etc from outside.

I want the private network to have all (clients') forward traffic on the fast connection and have the services accessible on all but no SNAT here.

The problem is that when somebody sends me a packet from outside on the slow eth the answer (I think) is sent through the fast connection, not the slow one.

How do I set up the routes/iptables rules to have my set up work properly?




PS:
- The behavior above appears even if I have no firewall, so I don't think is a firewall problem.
- i have watched with iptraf the traffic on the slow connection. I receive the ping req, but I don't see any reply (I will double check)
 
Old 01-26-2005, 02:38 AM   #2
fr_laz
Member
 
Registered: Jan 2005
Location: Cork Ireland
Distribution: Debian
Posts: 384

Rep: Reputation: 31
Hi,

What about your IP addressing ?

How many public IP(s) do you have, can you use one for www connection and one for the "fast" connection ?

If so, you could force the interface used to answer the www requests by using a feature called "NAT of local connexions" : thus you source-nat locally generated packet source port 80 to the IP of your slow ethernet interface...

I'm not sure that this will/could work....

Good luck !
 
Old 01-31-2005, 05:43 PM   #3
pe2338
Member
 
Registered: Dec 2002
Location: Bucharest,RO
Distribution: debian etch, sarge and sid
Posts: 407

Original Poster
Rep: Reputation: 30
weird, I didn't got any warning that I have an answer...

I found something that I think is the answer to my problem:

http://www.uwsg.iu.edu/hypermail/lin...07.0/0006.html

and the advanced routing howto

I hope this helps other people (I didn't tried it, but I have a very good feeling about this).


PS:
fr_laz: both the external interfaces have public IPs, but as I understand, you are trying some kind of change when the connection is made fro the inside, while I need incoming connections from outside to have their return packets sent correctly.

Thanks anyway. I will come back to announce if I succeded with the setup.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
routing problem: my LAN clients can't ping outside catoflu Linux - Networking 1 11-29-2005 06:03 PM
Installed everything ok.... weird LAN problem...... InfidelLewis Slackware 6 04-28-2005 12:08 PM
routing two isp connection to lan using linux box tisson Linux - Networking 2 09-08-2004 08:39 PM
Routing LAN -> WAN -> LAN with unhelpful router synx13 Linux - Networking 2 06-14-2004 02:35 PM
Weird ISP problem: expect (#) weppnesp Linux - Newbie 0 10-06-2002 12:37 PM


All times are GMT -5. The time now is 01:39 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration