Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #206210 > unrolled thread

Only using masquerading on internet facing server

Started byjohn doe <johndoe65534@mail.com>
First post2019-03-13 08:20 +0100
Last post2019-03-14 14:30 +0100
Articles 9 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  Only using masquerading on internet facing server john doe <johndoe65534@mail.com> - 2019-03-13 08:20 +0100
    Re: Only using masquerading on internet facing server Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-13 13:40 +0100
      Re: Only using masquerading on internet facing server john doe <johndoe65534@mail.com> - 2019-03-14 09:30 +0100
        Re: Only using masquerading on internet facing server mick crane <mick.crane@gmail.com> - 2019-03-14 09:40 +0100
        Re: Only using masquerading on internet facing server Joe <joe@jretrading.com> - 2019-03-14 10:20 +0100
          Re: Only using masquerading on internet facing server Dan Purgert <dan@djph.net> - 2019-03-14 12:00 +0100
        Re: Only using masquerading on internet facing server Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-14 14:00 +0100
          Re: Only using masquerading on internet facing server john doe <johndoe65534@mail.com> - 2019-03-14 16:50 +0100
        Re: Only using masquerading on internet facing server rhkramer@gmail.com - 2019-03-14 14:30 +0100

#206210 — Only using masquerading on internet facing server

Fromjohn doe <johndoe65534@mail.com>
Date2019-03-13 08:20 +0100
SubjectOnly using masquerading on internet facing server
Message-ID<xB6lc-i5-3@gated-at.bofh.it>
Hi,

I have one internet facing server that is doing masquerading (server a).
Behind that server I have an other server (server b).

Server a is the only one server that should do NAT .

Ip range on server a: 172.17.232.0/24
IP range on server b: 192.168.3.0/24

I have configured server a to MASQUERADE both IP ranges.

If I enable MASQUERADING on server b everything works as expected but as
soon as I disabled MASQUERADING on server b the hosts behind it don't
have internet access for example.
What do I need to do on server a to properly MASQUERADE server b?

P.S. Server a is on Debian Stretch.

--
John Doe

[toc] | [next] | [standalone]


#206228

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2019-03-13 13:40 +0100
Message-ID<xBbkS-3ni-9@gated-at.bofh.it>
In reply to#206210
> Ip range on server a: 172.17.232.0/24
> IP range on server b: 192.168.3.0/24

That's very vague.
But I'll assume that your "server b" has an address 172.17.232.NN
on one network interface and 192.168.3.1 on another.

> If I enable MASQUERADING on server b everything works as expected but as
> soon as I disabled MASQUERADING on server b the hosts behind it don't
> have internet access for example.
> What do I need to do on server a to properly MASQUERADE server b?

My guess is that on "server a" you have not setup routing so as to send
all the 192.168.3.0/24 packets to "server b".

IOW on "server a" you need to do something like

    route add -net 192.168.3.0/24 gw 172.17.232.NN
    

-- Stefan

[toc] | [prev] | [next] | [standalone]


#206252

Fromjohn doe <johndoe65534@mail.com>
Date2019-03-14 09:30 +0100
Message-ID<xBtUt-6Rr-7@gated-at.bofh.it>
In reply to#206228
On 3/13/2019 1:39 PM, Stefan Monnier wrote:
>> Ip range on server a: 172.17.232.0/24
>> IP range on server b: 192.168.3.0/24
>
> That's very vague.
> But I'll assume that your "server b" has an address 172.17.232.NN
> on one network interface and 192.168.3.1 on another.
>
>> If I enable MASQUERADING on server b everything works as expected but as
>> soon as I disabled MASQUERADING on server b the hosts behind it don't
>> have internet access for example.
>> What do I need to do on server a to properly MASQUERADE server b?
>
> My guess is that on "server a" you have not setup routing so as to send
> all the 192.168.3.0/24 packets to "server b".
>
> IOW on "server a" you need to do something like
>
>     route add -net 192.168.3.0/24 gw 172.17.232.NN
>
>

Thanks to anyone who has contributed to this question.

By the answers in this thread, I guess I need to explane what I have and
what I'm trying to do.

Server a and server b are identical, server a is the internet facing
server which has one network behind it (eth1 172.17.232.0/24 and eth0 is
the interface connected to the internet), server b is behind server a
and connected using the eth0 interface.
Server b is behind server a and is connected to server a through eth0,
server b has one network behind it (eth1 192.168.3.0/24).

For now both server (a and b) are responsible for MASQUERADING the
networks behind them.
So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs
192.168.3.0/24.

MASQUERADE is only needed on server a.

Does it help understanding what I'm trying to do?

I really appriciate any help/hint.

--
John Doe

[toc] | [prev] | [next] | [standalone]


#206253

Frommick crane <mick.crane@gmail.com>
Date2019-03-14 09:40 +0100
Message-ID<xBu49-6UV-3@gated-at.bofh.it>
In reply to#206252
On 2019-03-14 08:26, john doe wrote:
> On 3/13/2019 1:39 PM, Stefan Monnier wrote:
>>> Ip range on server a: 172.17.232.0/24
>>> IP range on server b: 192.168.3.0/24
>> 
>> That's very vague.
>> But I'll assume that your "server b" has an address 172.17.232.NN
>> on one network interface and 192.168.3.1 on another.
>> 
>>> If I enable MASQUERADING on server b everything works as expected but 
>>> as
>>> soon as I disabled MASQUERADING on server b the hosts behind it don't
>>> have internet access for example.
>>> What do I need to do on server a to properly MASQUERADE server b?
>> 
>> My guess is that on "server a" you have not setup routing so as to 
>> send
>> all the 192.168.3.0/24 packets to "server b".
>> 
>> IOW on "server a" you need to do something like
>> 
>>     route add -net 192.168.3.0/24 gw 172.17.232.NN
>> 
>> 
> 
> Thanks to anyone who has contributed to this question.
> 
> By the answers in this thread, I guess I need to explane what I have 
> and
> what I'm trying to do.
> 
> Server a and server b are identical, server a is the internet facing
> server which has one network behind it (eth1 172.17.232.0/24 and eth0 
> is
> the interface connected to the internet), server b is behind server a
> and connected using the eth0 interface.
> Server b is behind server a and is connected to server a through eth0,
> server b has one network behind it (eth1 192.168.3.0/24).
> 
> For now both server (a and b) are responsible for MASQUERADING the
> networks behind them.
> So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs
> 192.168.3.0/24.
> 
> MASQUERADE is only needed on server a.
> 
> Does it help understanding what I'm trying to do?
> 
> I really appriciate any help/hint.
> 
> --
> John Doe
put ipfire or pfsense on server a, they've got Guis for sorting out that 
stuff.

mick

-- 
Key ID    4BFEBB31

[toc] | [prev] | [next] | [standalone]


#206254

FromJoe <joe@jretrading.com>
Date2019-03-14 10:20 +0100
Message-ID<xBuGS-7oJ-3@gated-at.bofh.it>
In reply to#206252
On Thu, 14 Mar 2019 09:26:06 +0100
john doe <johndoe65534@mail.com> wrote:

> On 3/13/2019 1:39 PM, Stefan Monnier wrote:
> >> Ip range on server a: 172.17.232.0/24
> >> IP range on server b: 192.168.3.0/24  
> >
> > That's very vague.
> > But I'll assume that your "server b" has an address 172.17.232.NN
> > on one network interface and 192.168.3.1 on another.
> >  
> >> If I enable MASQUERADING on server b everything works as expected
> >> but as soon as I disabled MASQUERADING on server b the hosts
> >> behind it don't have internet access for example.
> >> What do I need to do on server a to properly MASQUERADE server b?  
> >
> > My guess is that on "server a" you have not setup routing so as to
> > send all the 192.168.3.0/24 packets to "server b".
> >
> > IOW on "server a" you need to do something like
> >
> >     route add -net 192.168.3.0/24 gw 172.17.232.NN
> >
> >  
> 
> Thanks to anyone who has contributed to this question.
> 
> By the answers in this thread, I guess I need to explane what I have
> and what I'm trying to do.
> 
> Server a and server b are identical, server a is the internet facing
> server which has one network behind it (eth1 172.17.232.0/24 and eth0
> is the interface connected to the internet), server b is behind
> server a and connected using the eth0 interface.
> Server b is behind server a and is connected to server a through eth0,
> server b has one network behind it (eth1 192.168.3.0/24).
> 
> For now both server (a and b) are responsible for MASQUERADING the
> networks behind them.
> So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs
> 192.168.3.0/24.
> 
> MASQUERADE is only needed on server a.
> 
> Does it help understanding what I'm trying to do?
> 
> I really appriciate any help/hint.

If workstation c connects to a public Internet server, how does the
reply get back to workstation c through servers a and b?

It has a private address, which nothing on the Net ever sees, so how can
a reply packet ever reach it?

The answer is that for both masquerading and stateful firewall
functioning, a router (and both of your servers are routers) must keep
a list of outgoing connections, and use it to process return packets for
the sending internal computer. The firewall lets the appropriate packets
in, the masquerade deals with the routing. Incoming replies leaving
server a will all have a destination address of server b. How is server
b to know what destination address to change it to? 

So yes, you do need masquerade on both servers. For server a, to
replace the incoming public destination address with that of server b,
and server b to replace *that* destination address with that of the
appropriate workstation.

I've always run like that, my router does masquerading and so does my
separate firewall. As far as I know, that doesn't stop any protocol
from passing through, though some (like ftp) need extra kernel modules
to associate two or more protocols or ports. 

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#206255

FromDan Purgert <dan@djph.net>
Date2019-03-14 12:00 +0100
Message-ID<xBwfE-8cF-7@gated-at.bofh.it>
In reply to#206254
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Joe wrote:
> On Thu, 14 Mar 2019 09:26:06 +0100
> john doe <johndoe65534@mail.com> wrote:
>> [...]
>> By the answers in this thread, I guess I need to explane what I have
>> and what I'm trying to do.
>> 
>> [...]
>> 
>> For now both server (a and b) are responsible for MASQUERADING the
>> networks behind them.
>> So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs
>> 192.168.3.0/24.
>> 
>> MASQUERADE is only needed on server a.
>> 
>> Does it help understanding what I'm trying to do?
>> 
>> I really appriciate any help/hint.
>
> If workstation c connects to a public Internet server, how does the
> reply get back to workstation c through servers a and b?
>
> It has a private address, which nothing on the Net ever sees, so how can
> a reply packet ever reach it?
> [...]
>
> So yes, you do need masquerade on both servers. For server a, to
> replace the incoming public destination address with that of server b,
> and server b to replace *that* destination address with that of the
> appropriate workstation.

This is incorrect.  He can add a routing entry to server A -- something
along the lines of:

  192.168.3.0/24 via 172.17.232.x 

The ".x" will have to be whatever IP address serverB has on the 172
network.  Once serverA knows how to get to "network_BC" (i.e.
192.168.3.0/24), serverB will no longer need to perform any NAT.

ServerA will still handle masquerade for all traffic exiting eth0 to the
internet, and the internet will be none the wiser.


-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEBcqaUD8uEzVNxUrujhHd8xJ5ooEFAlyKMb4ACgkQjhHd8xJ5
ooGGDQgAm+if7k3nGVaz2axefl7gGSqXuDut0A/3NnPJGQD18SaF7BV6pm21OypM
fPjxGvu044RQo1YmEPUWpgyz7uj7IRMaLpr5EkbceMsTPOyLTMBcSSjuPURJpTko
UdH7VwUo+gkzqV3uhTqgzYaUngfq80qTt2NHJQrUIzvNrWg3tjO4ccFJn6U3h40K
Mnb4+u4AM9G9857O7RuXHqkkXeQ2nMqKY+2BpL0+10qsP6TdrlQFj/M2VOoxtNgI
/tokgvps1DC7XTu1JbDtY0u+7WugTTAaer2ZKSMuNpDtE/2+qADjFuP/XQuRjTQ+
vQj9SmzNN4+HC23unSzNU7LMNsB7+g==
=bcsD
-----END PGP SIGNATURE-----

-- 
|_|O|_| 
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#206256

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2019-03-14 14:00 +0100
Message-ID<xBy7L-VE-3@gated-at.bofh.it>
In reply to#206252
> Does it help understanding what I'm trying to do?

It just confirms what I guessed.  Did you try my suggestion?


        Stefan

[toc] | [prev] | [next] | [standalone]


#206260

Fromjohn doe <johndoe65534@mail.com>
Date2019-03-14 16:50 +0100
Message-ID<xBAMi-2Bz-5@gated-at.bofh.it>
In reply to#206256
On 3/14/2019 1:58 PM, Stefan Monnier wrote:
>> Does it help understanding what I'm trying to do?
>
> It just confirms what I guessed.  Did you try my suggestion?
>

Thanks to Your answer and the one by "Dan Purgert <dan@djph.net>" I now
have the bit I was missing; add routing on server a to let server a know
about server b! :)

Time to read on routing and routes! :)

Thanks to both of you and the  folks who has contributed to this thread.

--
John Doe

[toc] | [prev] | [next] | [standalone]


#206257

Fromrhkramer@gmail.com
Date2019-03-14 14:30 +0100
Message-ID<xByAN-1kQ-3@gated-at.bofh.it>
In reply to#206252
On Thursday, March 14, 2019 04:26:06 AM john doe wrote:
> By the answers in this thread, I guess I need to explane what I have and
> what I'm trying to do.

As someone observing from the peanut gallery, it would help me if the 
explanation was a little less detailed -- sort of an overview.

Let me make a guess, using maybe some acronyms (which I should probably try to 
avoid).

I'm guessing that you have a private LAN (192.168.3.0) behind server b, with 
no direct connection to the Internet.  

Ahead of that, to provide a connection to the Internet, you have server A.

The combination of the two is intended to create a DMZ (iirc) -- a place where 
you can put computers / servers that are more accessible from outside the LAN.

Close???






> 
> Server a and server b are identical, server a is the internet facing
> server which has one network behind it (eth1 172.17.232.0/24 and eth0 is
> the interface connected to the internet), server b is behind server a
> and connected using the eth0 interface.
> Server b is behind server a and is connected to server a through eth0,
> server b has one network behind it (eth1 192.168.3.0/24).
> 
> For now both server (a and b) are responsible for MASQUERADING the
> networks behind them.
> So server a MASQUERADEs 172.17.232.0/24 and server b MASQUERADEs
> 192.168.3.0/24.
> 
> MASQUERADE is only needed on server a.
> 
> Does it help understanding what I'm trying to do?
> 
> I really appriciate any help/hint.
> 
> --
> John Doe

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web