NAT config questions...

Daniel Augusto Fernandes daftm@gcsnet.com.br
Sat, 11 Nov 2000 12:37:40 -0200


Hello people,

I've been using netfilter with success for some time but I have some
questions about NAT configuration.

I have this scenario (by a non ASCII artist: me!! :o) )

                                                    Internet
                                                       v
|---------|                                            |
|         |                                    |-------------|
| Private |                                    |   Router    |
|   Net   |                                    |-------------|
|         |                       (dev=200.234.219.209)|
|---------|                        (200.234.219.208/29)|
     |(129.0.0.0/24)                                   |
     |                                                 |
     |                   |----------|                  |
     |      (129.0.0.100)|          |(200.234.219.210) |
     |-------------------| Firewall |-------------------
                   (eth1)|   NAT    |(eth0)
                         |          |
                         |----------|

My doubt is:
How is the best way to make the Private Net able to access the internet
throught the Firewall+NAT?

I have IP's from 129.0.0.1-129.0.0.254 and 129.0.1.1-129.0.1.254. Should
I configure SNAT and DNAT for all these addresses? Would I have to
config IP aliases in eth0 for each of thoses IP's?

Your help would be really appreciated! I just wanna show my client that
linux+iptables are much better than any Wingate he would get... :o)



--------------------------------------------------------------------
Daniel Augusto Fernandes (DAF tm)               daftm@gcsnet.com.br
GCSNet                                    http://www.gcsnet.com.br/
--------------------------------------------------------------------
                     Se você não encontra
                     o sentido das coisas
                     é porque este não
                     se encontra, se cria.
                                   Antoine Saint-Exupéry