Help with usage “ip rule add fwmark 0x24 table T3” with NAT in the
SLES11SP1
Enviroment:
SERVER - SLES11SP1
eth3 - local lan interface (192.168.252.11 with netmask 255.255.255.0)
eth0 - Internet interface to ISP1 (default gateway)
vlan121 - Internet interface to ISP2
WS - sles10. eth0[192.168.252.17]
This variant works:
/usr/sbin/iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to
213.130.10.242
/usr/sbin/iptables -t nat -A POSTROUTING -o vlan121 -j SNAT --to
195.184.194.34
P1_NETV121=“195.184.194.32/30”
IF1V121=“vlan121”
IP1V121=“195.184.194.34”
P1V121=“195.184.194.33”
/sbin/ip route add $P1_NETV121 dev $IF1V121 src $IP1V121 table T3
/sbin/ip route add default via $P1V121 table T3
/sbin/ip rule add from $IP1V121 table T3
/sbin/ip route add 192.168.252.0/24 dev eth3 table T3
/sbin/ip route add 127.0.0.0/8 dev lo table T3
/sbin/ip rule add from 192.168.252.17 table T3
/sbin/ip route flush cache
After this can do from the WS #telnetww.novell.com
GET /
And after this all pakets from the WS go over vlan121.
This is OK !
If instead of “/sbin/ip rule add from 192.168.252.17 table T3” to
use:
/sbin/ip rule del from 192.168.252.17 table T3
/sbin/ip rule add fwmark 0x24 table T3
/usr/sbin/iptables -t mangle -A PREROUTING -i eth3 -s 192.168.252.17
-j MARK --set-mark 0x24
/sbin/ip route flush cache
Packets leave through interface VLAN121 in the Internet, come the
answer to interface VLAN121 from the Internet, but answers from VLAN121
don’t go anywhere further
Help with usage “ip rule add fwmark 0x24 table T3” with NAT in the
SLES11SP1
Enviroment:
SERVER - SLES11SP1
eth3 - local lan interface (192.168.252.11 with netmask 255.255.255.0)
eth0 - Internet interface to ISP1 (default gateway)
vlan121 - Internet interface to ISP2
WS - sles10. eth0[192.168.252.17]
This variant works:
/usr/sbin/iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to
213.130.10.242
/usr/sbin/iptables -t nat -A POSTROUTING -o vlan121 -j SNAT --to
195.184.194.34
P1_NETV121=“195.184.194.32/30”
IF1V121=“vlan121”
IP1V121=“195.184.194.34”
P1V121=“195.184.194.33”
/sbin/ip route add $P1_NETV121 dev $IF1V121 src $IP1V121 table T3
/sbin/ip route add default via $P1V121 table T3
/sbin/ip rule add from $IP1V121 table T3
/sbin/ip route add 192.168.252.0/24 dev eth3 table T3
/sbin/ip route add 127.0.0.0/8 dev lo table T3
/sbin/ip rule add from 192.168.252.17 table T3
/sbin/ip route flush cache
After this can do from the WS #telnetww.novell.com
GET /
And after this all pakets from the WS go over vlan121.
This is OK !
If instead of “/sbin/ip rule add from 192.168.252.17 table T3” to
use:
/sbin/ip rule del from 192.168.252.17 table T3
/sbin/ip rule add fwmark 0x24 table T3
/usr/sbin/iptables -t mangle -A PREROUTING -i eth3 -s 192.168.252.17
-j MARK --set-mark 0x24
/sbin/ip route flush cache
Packets leave through interface VLAN121 in the Internet, come the
answer to interface VLAN121 from the Internet, but answers from VLAN121
don’t go anywhere further
Please, help me.
Serg[/color]
After this
sysctl net.ipv4.conf.all.rp_filter=0
all work !!!