Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #206210 > unrolled thread
| Started by | john doe <johndoe65534@mail.com> |
|---|---|
| First post | 2019-03-13 08:20 +0100 |
| Last post | 2019-03-14 14:30 +0100 |
| Articles | 9 — 6 participants |
Back to article view | Back to linux.debian.user
Only using masquerading on internet facing server john doe <johndoe65534@mail.com> - 2019-03-13 08:20 +0100
Re: Only using masquerading on internet facing server Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-13 13:40 +0100
Re: Only using masquerading on internet facing server john doe <johndoe65534@mail.com> - 2019-03-14 09:30 +0100
Re: Only using masquerading on internet facing server mick crane <mick.crane@gmail.com> - 2019-03-14 09:40 +0100
Re: Only using masquerading on internet facing server Joe <joe@jretrading.com> - 2019-03-14 10:20 +0100
Re: Only using masquerading on internet facing server Dan Purgert <dan@djph.net> - 2019-03-14 12:00 +0100
Re: Only using masquerading on internet facing server Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-14 14:00 +0100
Re: Only using masquerading on internet facing server john doe <johndoe65534@mail.com> - 2019-03-14 16:50 +0100
Re: Only using masquerading on internet facing server rhkramer@gmail.com - 2019-03-14 14:30 +0100
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2019-03-13 08:20 +0100 |
| Subject | Only using masquerading on internet facing server |
| Message-ID | <xB6lc-i5-3@gated-at.bofh.it> |
Hi, I have one internet facing server that is doing masquerading (server a). Behind that server I have an other server (server b). Server a is the only one server that should do NAT . Ip range on server a: 172.17.232.0/24 IP range on server b: 192.168.3.0/24 I have configured server a to MASQUERADE both IP ranges. If I enable MASQUERADING on server b everything works as expected but as soon as I disabled MASQUERADING on server b the hosts behind it don't have internet access for example. What do I need to do on server a to properly MASQUERADE server b? P.S. Server a is on Debian Stretch. -- John Doe
[toc] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2019-03-13 13:40 +0100 |
| Message-ID | <xBbkS-3ni-9@gated-at.bofh.it> |
| In reply to | #206210 |
> Ip range on server a: 172.17.232.0/24
> IP range on server b: 192.168.3.0/24
That's very vague.
But I'll assume that your "server b" has an address 172.17.232.NN
on one network interface and 192.168.3.1 on another.
> If I enable MASQUERADING on server b everything works as expected but as
> soon as I disabled MASQUERADING on server b the hosts behind it don't
> have internet access for example.
> What do I need to do on server a to properly MASQUERADE server b?
My guess is that on "server a" you have not setup routing so as to send
all the 192.168.3.0/24 packets to "server b".
IOW on "server a" you need to do something like
route add -net 192.168.3.0/24 gw 172.17.232.NN
-- Stefan
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2019-03-14 09:30 +0100 |
| Message-ID | <xBtUt-6Rr-7@gated-at.bofh.it> |
| In reply to | #206228 |
On 3/13/2019 1:39 PM, Stefan Monnier wrote: >> Ip range on server a: 172.17.232.0/24 >> IP range on server b: 192.168.3.0/24 > > That's very vague. > But I'll assume that your "server b" has an address 172.17.232.NN > on one network interface and 192.168.3.1 on another. > >> If I enable MASQUERADING on server b everything works as expected but as >> soon as I disabled MASQUERADING on server b the hosts behind it don't >> have internet access for example. >> What do I need to do on server a to properly MASQUERADE server b? > > My guess is that on "server a" you have not setup routing so as to send > all the 192.168.3.0/24 packets to "server b". > > IOW on "server a" you need to do something like > > route add -net 192.168.3.0/24 gw 172.17.232.NN > > Thanks to anyone who has contributed to this question. By the answers in this thread, I guess I need to explane what I have and what I'm trying to do. Server a and server b are identical, server a is the internet facing server which has one network behind it (eth1 172.17.232.0/24 and eth0 is the interface connected to the internet), server b is behind server a and connected using the eth0 interface. Server b is behind server a and is connected to server a through eth0, server b has one network behind it (eth1 192.168.3.0/24). For now both server (a and b) are responsible for MASQUERADING the networks behind them. So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs 192.168.3.0/24. MASQUERADE is only needed on server a. Does it help understanding what I'm trying to do? I really appriciate any help/hint. -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | mick crane <mick.crane@gmail.com> |
|---|---|
| Date | 2019-03-14 09:40 +0100 |
| Message-ID | <xBu49-6UV-3@gated-at.bofh.it> |
| In reply to | #206252 |
On 2019-03-14 08:26, john doe wrote: > On 3/13/2019 1:39 PM, Stefan Monnier wrote: >>> Ip range on server a: 172.17.232.0/24 >>> IP range on server b: 192.168.3.0/24 >> >> That's very vague. >> But I'll assume that your "server b" has an address 172.17.232.NN >> on one network interface and 192.168.3.1 on another. >> >>> If I enable MASQUERADING on server b everything works as expected but >>> as >>> soon as I disabled MASQUERADING on server b the hosts behind it don't >>> have internet access for example. >>> What do I need to do on server a to properly MASQUERADE server b? >> >> My guess is that on "server a" you have not setup routing so as to >> send >> all the 192.168.3.0/24 packets to "server b". >> >> IOW on "server a" you need to do something like >> >> route add -net 192.168.3.0/24 gw 172.17.232.NN >> >> > > Thanks to anyone who has contributed to this question. > > By the answers in this thread, I guess I need to explane what I have > and > what I'm trying to do. > > Server a and server b are identical, server a is the internet facing > server which has one network behind it (eth1 172.17.232.0/24 and eth0 > is > the interface connected to the internet), server b is behind server a > and connected using the eth0 interface. > Server b is behind server a and is connected to server a through eth0, > server b has one network behind it (eth1 192.168.3.0/24). > > For now both server (a and b) are responsible for MASQUERADING the > networks behind them. > So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs > 192.168.3.0/24. > > MASQUERADE is only needed on server a. > > Does it help understanding what I'm trying to do? > > I really appriciate any help/hint. > > -- > John Doe put ipfire or pfsense on server a, they've got Guis for sorting out that stuff. mick -- Key ID 4BFEBB31
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2019-03-14 10:20 +0100 |
| Message-ID | <xBuGS-7oJ-3@gated-at.bofh.it> |
| In reply to | #206252 |
On Thu, 14 Mar 2019 09:26:06 +0100 john doe <johndoe65534@mail.com> wrote: > On 3/13/2019 1:39 PM, Stefan Monnier wrote: > >> Ip range on server a: 172.17.232.0/24 > >> IP range on server b: 192.168.3.0/24 > > > > That's very vague. > > But I'll assume that your "server b" has an address 172.17.232.NN > > on one network interface and 192.168.3.1 on another. > > > >> If I enable MASQUERADING on server b everything works as expected > >> but as soon as I disabled MASQUERADING on server b the hosts > >> behind it don't have internet access for example. > >> What do I need to do on server a to properly MASQUERADE server b? > > > > My guess is that on "server a" you have not setup routing so as to > > send all the 192.168.3.0/24 packets to "server b". > > > > IOW on "server a" you need to do something like > > > > route add -net 192.168.3.0/24 gw 172.17.232.NN > > > > > > Thanks to anyone who has contributed to this question. > > By the answers in this thread, I guess I need to explane what I have > and what I'm trying to do. > > Server a and server b are identical, server a is the internet facing > server which has one network behind it (eth1 172.17.232.0/24 and eth0 > is the interface connected to the internet), server b is behind > server a and connected using the eth0 interface. > Server b is behind server a and is connected to server a through eth0, > server b has one network behind it (eth1 192.168.3.0/24). > > For now both server (a and b) are responsible for MASQUERADING the > networks behind them. > So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs > 192.168.3.0/24. > > MASQUERADE is only needed on server a. > > Does it help understanding what I'm trying to do? > > I really appriciate any help/hint. If workstation c connects to a public Internet server, how does the reply get back to workstation c through servers a and b? It has a private address, which nothing on the Net ever sees, so how can a reply packet ever reach it? The answer is that for both masquerading and stateful firewall functioning, a router (and both of your servers are routers) must keep a list of outgoing connections, and use it to process return packets for the sending internal computer. The firewall lets the appropriate packets in, the masquerade deals with the routing. Incoming replies leaving server a will all have a destination address of server b. How is server b to know what destination address to change it to? So yes, you do need masquerade on both servers. For server a, to replace the incoming public destination address with that of server b, and server b to replace *that* destination address with that of the appropriate workstation. I've always run like that, my router does masquerading and so does my separate firewall. As far as I know, that doesn't stop any protocol from passing through, though some (like ftp) need extra kernel modules to associate two or more protocols or ports. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2019-03-14 12:00 +0100 |
| Message-ID | <xBwfE-8cF-7@gated-at.bofh.it> |
| In reply to | #206254 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Joe wrote: > On Thu, 14 Mar 2019 09:26:06 +0100 > john doe <johndoe65534@mail.com> wrote: >> [...] >> By the answers in this thread, I guess I need to explane what I have >> and what I'm trying to do. >> >> [...] >> >> For now both server (a and b) are responsible for MASQUERADING the >> networks behind them. >> So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs >> 192.168.3.0/24. >> >> MASQUERADE is only needed on server a. >> >> Does it help understanding what I'm trying to do? >> >> I really appriciate any help/hint. > > If workstation c connects to a public Internet server, how does the > reply get back to workstation c through servers a and b? > > It has a private address, which nothing on the Net ever sees, so how can > a reply packet ever reach it? > [...] > > So yes, you do need masquerade on both servers. For server a, to > replace the incoming public destination address with that of server b, > and server b to replace *that* destination address with that of the > appropriate workstation. This is incorrect. He can add a routing entry to server A -- something along the lines of: 192.168.3.0/24 via 172.17.232.x The ".x" will have to be whatever IP address serverB has on the 172 network. Once serverA knows how to get to "network_BC" (i.e. 192.168.3.0/24), serverB will no longer need to perform any NAT. ServerA will still handle masquerade for all traffic exiting eth0 to the internet, and the internet will be none the wiser. -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEBcqaUD8uEzVNxUrujhHd8xJ5ooEFAlyKMb4ACgkQjhHd8xJ5 ooGGDQgAm+if7k3nGVaz2axefl7gGSqXuDut0A/3NnPJGQD18SaF7BV6pm21OypM fPjxGvu044RQo1YmEPUWpgyz7uj7IRMaLpr5EkbceMsTPOyLTMBcSSjuPURJpTko UdH7VwUo+gkzqV3uhTqgzYaUngfq80qTt2NHJQrUIzvNrWg3tjO4ccFJn6U3h40K Mnb4+u4AM9G9857O7RuXHqkkXeQ2nMqKY+2BpL0+10qsP6TdrlQFj/M2VOoxtNgI /tokgvps1DC7XTu1JbDtY0u+7WugTTAaer2ZKSMuNpDtE/2+qADjFuP/XQuRjTQ+ vQj9SmzNN4+HC23unSzNU7LMNsB7+g== =bcsD -----END PGP SIGNATURE----- -- |_|O|_| |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2019-03-14 14:00 +0100 |
| Message-ID | <xBy7L-VE-3@gated-at.bofh.it> |
| In reply to | #206252 |
> Does it help understanding what I'm trying to do?
It just confirms what I guessed. Did you try my suggestion?
Stefan
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2019-03-14 16:50 +0100 |
| Message-ID | <xBAMi-2Bz-5@gated-at.bofh.it> |
| In reply to | #206256 |
On 3/14/2019 1:58 PM, Stefan Monnier wrote: >> Does it help understanding what I'm trying to do? > > It just confirms what I guessed. Did you try my suggestion? > Thanks to Your answer and the one by "Dan Purgert <dan@djph.net>" I now have the bit I was missing; add routing on server a to let server a know about server b! :) Time to read on routing and routes! :) Thanks to both of you and the folks who has contributed to this thread. -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2019-03-14 14:30 +0100 |
| Message-ID | <xByAN-1kQ-3@gated-at.bofh.it> |
| In reply to | #206252 |
On Thursday, March 14, 2019 04:26:06 AM john doe wrote: > By the answers in this thread, I guess I need to explane what I have and > what I'm trying to do. As someone observing from the peanut gallery, it would help me if the explanation was a little less detailed -- sort of an overview. Let me make a guess, using maybe some acronyms (which I should probably try to avoid). I'm guessing that you have a private LAN (192.168.3.0) behind server b, with no direct connection to the Internet. Ahead of that, to provide a connection to the Internet, you have server A. The combination of the two is intended to create a DMZ (iirc) -- a place where you can put computers / servers that are more accessible from outside the LAN. Close??? > > Server a and server b are identical, server a is the internet facing > server which has one network behind it (eth1 172.17.232.0/24 and eth0 is > the interface connected to the internet), server b is behind server a > and connected using the eth0 interface. > Server b is behind server a and is connected to server a through eth0, > server b has one network behind it (eth1 192.168.3.0/24). > > For now both server (a and b) are responsible for MASQUERADING the > networks behind them. > So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs > 192.168.3.0/24. > > MASQUERADE is only needed on server a. > > Does it help understanding what I'm trying to do? > > I really appriciate any help/hint. > > -- > John Doe
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web