LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-11-2007, 12:24 AM   #1
elfoozo
Member
 
Registered: Feb 2004
Location: Washington, USA
Distribution: Debian
Posts: 265

Rep: Reputation: 32
Strict Routing


Is this possible within one box with one NIC?

Code:
                                                                      _
                                            +-----------+            /
                                        +---| ext-ip5   |-----------|
                                        |   +-----------+          /
        __                              |                         |
    ___/  \_         +----------------+ |   +-----------+        /
   /        \_       |            ip5 +-+   | ext-ip4   |-------|
  /           \      |  +----+        |    /+-----------+      /
 |             \     |  |eth0|    ip4 +---+                    |
/               |    |  |    |        |     +-----------+      |
| Local network -----+  +----+    ip3 +-----| ext-ip3   |------|Internet
\               |    |                |     +-----------+      |
 \_            /     |            ip2 +---+                    |
   \         _/      |                |    \+-----------+      \
    \_     _/        |            ip1 +-+   | ext-ip2   |-------|
      \___/          +----------------+ |   +-----------+        \
                                        |                         |
                                        |   +-----------+          \
                                        +---| ext-ip1   |-----------|
                                            +-----------+            \_

Assuming ext-ip 1-5 are Internet facing IP's that are NAT'ed to an internal virtual local IP and the Linux host only has 1 physical NIC, Is it possible for each virtual IP to only respond & route traffic to & from its specific IP?

Like mini gateways or pvc's or single IP vlan's something?

The goal is that any of the 5 local IP's respond to Internet requests as if they were unique individual hosts and the reply would only come from the IP it came "in" through, not step back out through a "default gateway".

I read through the advanced routing guide and I didn't see where gateways could be established if the internal ip's were all on the same subnet, a.k.a. internal ip1 was 192.168.1.1, internal ip2 was 192.168.1.2, etc., etc.
 
Old 12-12-2007, 08:06 PM   #2
dkm999
Member
 
Registered: Nov 2006
Location: Seattle, WA
Distribution: Fedora
Posts: 407

Rep: Reputation: 35
If you want to do this in a perfectly general way, I think you will have to preserve the 5-IP scheme on the local side of your firewall. This should be possible by overlaying several private subnets on the same cable and interface. (You could even crank the netmask down to 255.255.255.252, and only use up 4 addresses per subnet, if you are really into this stuff.)

But if you want to use NAT just to direct specific ports to specific servers, then the return traffic for that port will be automagically sent back out on the original incoming IP address when the NAT code gets the reply packet from your server.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall policy too strict? Azalar Linux - Security 16 10-25-2007 05:31 PM
Perl poblem with strict.pm Atrocity Slackware 4 04-29-2005 08:08 AM
strict usergroup ?? how to ?? help plz Mr.Bingles Linux - Networking 0 06-07-2004 01:03 AM
Am i right, wrong or just to strict in my views? BajaNick General 23 01-15-2004 08:20 PM
Strict DHCP puzz_1 Linux - Networking 8 06-05-2003 12:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration