View previous topic :: View next topic |
Author |
Message |
homeobocks Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/5bf85/5bf85a27af0dbe5bbf4d2a429439ddae72ff7a00" alt=""
Joined: 19 Dec 2003 Posts: 345 Location: I'm from Canada, and they say I'm a little slow . . . eh?
|
Posted: Wed Feb 04, 2004 2:55 am Post subject: Sharing Internet Connection |
|
|
Here's the situation. There are two computers involved. Greedo is a Windows XP box (not mine, my family's), and IG-88 is a Gentoo box. IG-88 connects to Greedo from IG-88.eth0, to Greedo.eth1. Greedo.eth2 conencts to the internet. I am going to install Gentoo on another hdd on Greedo, but I still want the connection to be shared (so IG-88 can access the internet). This diagram should clear things up:
Code: |
+-------------+ +----------------+
Internet===+----+ Greedo |----+====+----+ IG-88 |
|eth0| |eth1| |eth0| |
+----+-------------+----+ +----+----------------+ |
Anyways, I am going to do the Knoppix install. How would I make the connection shared? Please explain it well, as I am a recent RedHat convert.
Thanks a lot. _________________ HOW DO I SHOT WEB |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
homeobocks Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/5bf85/5bf85a27af0dbe5bbf4d2a429439ddae72ff7a00" alt=""
Joined: 19 Dec 2003 Posts: 345 Location: I'm from Canada, and they say I'm a little slow . . . eh?
|
Posted: Wed Feb 04, 2004 5:40 am Post subject: |
|
|
bump _________________ HOW DO I SHOT WEB |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
homeobocks Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/5bf85/5bf85a27af0dbe5bbf4d2a429439ddae72ff7a00" alt=""
Joined: 19 Dec 2003 Posts: 345 Location: I'm from Canada, and they say I'm a little slow . . . eh?
|
Posted: Wed Feb 04, 2004 7:35 pm Post subject: |
|
|
bump data:image/s3,"s3://crabby-images/53661/53661a150e021c20e4c55803116603b7f6c17337" alt="Evil or Very Mad :evil:" _________________ HOW DO I SHOT WEB |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
triwebb1 Tux's lil' helper
data:image/s3,"s3://crabby-images/bc27a/bc27a0391196ce67cfff4c0ec96ac0b8f77d0350" alt="Tux's lil' helper Tux's lil' helper"
Joined: 19 Oct 2003 Posts: 87
|
Posted: Wed Feb 04, 2004 11:33 pm Post subject: |
|
|
It is called masquerading in linux. Do this on Greedo:
Code: | iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward |
That will enable masquerading going out your external interface, and allow ip forwarding. This is NAT/PAT. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
john7002 Apprentice
data:image/s3,"s3://crabby-images/ea29a/ea29a4cbd68e0e1eea77308b308be178c4bce818" alt="Apprentice Apprentice"
data:image/s3,"s3://crabby-images/f400a/f400a6edb87b1ad84fe1971ffd37669a89726b12" alt=""
Joined: 21 Jan 2004 Posts: 238 Location: United Kingdom
|
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
homeobocks Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/5bf85/5bf85a27af0dbe5bbf4d2a429439ddae72ff7a00" alt=""
Joined: 19 Dec 2003 Posts: 345 Location: I'm from Canada, and they say I'm a little slow . . . eh?
|
Posted: Thu Feb 05, 2004 3:01 am Post subject: |
|
|
triwebb1 wrote: | It is called masquerading in linux. Do this on Greedo:
Code: | iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward |
That will enable masquerading going out your external interface, and allow ip forwarding. This is NAT/PAT. |
When I do the first command, I get this message: Code: | iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADEWarning: weird character in interface `-j' (No aliases, :, ! or *).
Bad argument `MASQUERADE'
Try `iptables -h' or 'iptables --help' for more information.
|
I also tried with SNAT, but with the same results (s/MASQUERADE/SNAT). _________________ HOW DO I SHOT WEB |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
aerandir n00b
data:image/s3,"s3://crabby-images/14c20/14c20699cdf7e07ed6ab9b097e628fa30cacbd62" alt="n00b n00b"
Joined: 09 Jan 2004 Posts: 13 Location: Denmark
|
Posted: Thu Feb 05, 2004 3:18 am Post subject: |
|
|
do you have masquarading (and other relevant netfilter parts) enabled in your kernel?
Code: | gauntlet:/usr/src/linux# grep MASQ .config
CONFIG_IP_NF_TARGET_MASQUERADE=m |
I usually enable all netfilter stuff as modules and then load the ones I need.. |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
homeobocks Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/5bf85/5bf85a27af0dbe5bbf4d2a429439ddae72ff7a00" alt=""
Joined: 19 Dec 2003 Posts: 345 Location: I'm from Canada, and they say I'm a little slow . . . eh?
|
Posted: Thu Feb 05, 2004 9:39 pm Post subject: |
|
|
aerandir wrote: | do you have masquarading (and other relevant netfilter parts) enabled in your kernel?
Code: | gauntlet:/usr/src/linux# grep MASQ .config
CONFIG_IP_NF_TARGET_MASQUERADE=m |
I usually enable all netfilter stuff as modules and then load the ones I need.. |
Yeah, Knoppix 3.3 has masquarading in the kernel. _________________ HOW DO I SHOT WEB |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
homeobocks Guru
data:image/s3,"s3://crabby-images/55cad/55cadf22bfc4066b9cbef86ab0e8bd0c53423b93" alt="Guru Guru"
data:image/s3,"s3://crabby-images/5bf85/5bf85a27af0dbe5bbf4d2a429439ddae72ff7a00" alt=""
Joined: 19 Dec 2003 Posts: 345 Location: I'm from Canada, and they say I'm a little slow . . . eh?
|
Posted: Fri Feb 06, 2004 7:40 pm Post subject: |
|
|
bump _________________ HOW DO I SHOT WEB |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
ClausH n00b
data:image/s3,"s3://crabby-images/14c20/14c20699cdf7e07ed6ab9b097e628fa30cacbd62" alt="n00b n00b"
Joined: 03 Aug 2003 Posts: 58 Location: Herning, denmark
|
Posted: Fri Feb 06, 2004 10:14 pm Post subject: |
|
|
homeobocks wrote: | triwebb1 wrote: | It is called masquerading in linux. Do this on Greedo:
Code: | iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward |
That will enable masquerading going out your external interface, and allow ip forwarding. This is NAT/PAT. |
When I do the first command, I get this message: Code: | iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADEWarning: weird character in interface `-j' (No aliases, :, ! or *).
Bad argument `MASQUERADE'
Try `iptables -h' or 'iptables --help' for more information.
|
I also tried with SNAT, but with the same results (s/MASQUERADE/SNAT). |
Did you set $EXTIF to your external interface eg.
And if your default policies are not set do ACCEPT, you will need
Code: |
iptables -A FORWARD -i $EXTIF -o $INTIF -m state --state ESTABLISHED,RELATED -j ACCEPT
|
with $INTIF being the internal interface.
Mvh Claus Holmgaard |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|