Traduisez - Übersetzen - Traduzca - Traduza - Tradurre - Translate
Kevin G. Eliuk (kg@dccnet.com)
Thu, 04 Jan 2001 23:47:50 -0800
Gabriel Mastico wrote:
>
> > I am a little vague with natd(8), but the one parameter that would possibly
> > allow this could be the combination of '-interface -alias_address address
> > -target_address address', if I am reading it correctly. Correct me if please if
> > you know I am not.
>
> are you referring to -redirect_address internal.address:port-port port2-port2
> where internal.address is the host you wish to forwardto, port-port is the port range
> you wish to forward to on internal.adress, and port2-port2 is the port range on the
> outside interface?
> that's how it is in 4.2, at any rate
No :-)
-alias_address | -a address
Use address as the aliasing address. If this option is not
specified, the -interface option must be used. The specified
address is usually the address assigned to the ``public''
network interface.
All data passing out will be rewritten with a source address
equal to address. All data coming in will be checked to see
if it matches any already-aliased outgoing connection. If it
does, the packet is altered accordingly. If not, all
-redirect_port, -redirect_proto and -redirect_address assign-
ments are checked and actioned. If no other action can be
made and if -deny_incoming is not specified, the packet is
delivered to the local machine using the rules specified in
-target_address option below.
-t | -target_address address
Set the target address. When an incoming packet not associ-
ated with any pre-existing link arrives at the host machine,
it will be sent to the specified address.
The target address may be set to 255.255.255.255, in which
case all new incoming packets go to the alias address set by
-alias_address or -interface.
If this option is not used, or called with the argument
0.0.0.0, then all new incoming packets go to the address
specified in the packet. This allows external machines to
talk directly to internal machines if they can route packets
to the machine in question.
This seems to be the only optional flags that would apply to the configuration
that you are shooting for.
--
Regards, | Any and all errors in spelling are the
| intellectual property of the author and
Kevin G. Eliuk <kg@dccnet.com> | are therefore governed by the copyright
| laws of the jurisdiction in which they
(604) 886-4040 | are received.
--
This message came to you via the Vancouver Linux Users Group mailing list.
For unsubscription instructions do not email the list, but rather send mail
to <vanlug-request@gweep.bc.ca>.
This archive was generated by hypermail 2.0b3 on Fri 05 Jan 2001 - 07:49:55