1 |
Grant Edwards wrote: |
2 |
> I found shorewall and firestarter, but neither looked very |
3 |
> useful to me: |
4 |
> |
5 |
> 1) They're both designed for configuring firewalls, and I'm |
6 |
> not building a firewall machine. |
7 |
> |
8 |
> 2) Neither seemed to have any way to specify port-based routing. |
9 |
> |
10 |
> So it looks like plain iptables is the way to go. |
11 |
> |
12 |
|
13 |
I'm not aware of any iptables front end that will also manager policy |
14 |
based routing which is Cisco-ese and maybe general Network-ese for what |
15 |
you're trying to do. However I would use shorewall (or whatever you |
16 |
prefer) to do most of the work and then insert your custom rules where |
17 |
they need to go. |
18 |
All policy routing regardless of actual implementation has you build an |
19 |
ACL of traffic you'd like messed with. Then you need to specify what |
20 |
happens to traffic that matches the ACL. However one thing the original |
21 |
how-to you linked left didn't completely spell out is NAT. You MUST NAT |
22 |
on each interface or you'll have all sorts of routing fun that does not |
23 |
work. |
24 |
|
25 |
kashani |
26 |
-- |
27 |
gentoo-user@l.g.o mailing list |