Jump to content

MNF and 2 gateways (again..again)


Guest stuck_techy
 Share

Recommended Posts

Guest stuck_techy

hello all,

 

i know this topic has user guides (ive read some of them) but i still need help...

 

First of all, to avoid lines of explaining everything, ive attached a badly drawn pic to help.

 

Secondly, I would like to know if there are any user guides specific to the web admin interface for MNF (on the cd they are all based as if u are logged into x-window). This would be a great help.

 

Finally (just in case nebody has any *easy* suggestion) the problem:

the 'clients' need to access a host 'www.host.com' (the ip changes) on a remote network (gateway 192.168.0.2), i have a route to the remote dns which appears to work (it resolves) using a windows server.

In addition, the 'clients' also have to have internet access via gateway 192.168.0.1.

Unfortunately windows only allows me to 1 gateway at a time, not both.

 

My idea is to use linux (i have not used it before though) as an internal firewall, router and DNS which will route all traffic for a particular hostname through 1 gateway whilst still allowing internet access. If i am better off using Mandrake 10 than MNF then that is no problem at this stage.

 

any help or advice greatly appreciated!

example.bmp

Link to comment
Share on other sites

Looks interesting...

 

Can you give a little more detail - I don't quite understand what you are trying to do...

 

The DNS server is on a private network - have you any control over it, i.e. can you get requests on port 80 forwarded to the target host, so all you have to do is use the public IP address? Then you wouldn't need the remote DNS server. Or perhaps have a VPN set up?

 

Or is it the public address that is dynamic? In this case there are services that will run a DNS server for you - haven't tried it though.

 

I am wondering why you have 2 gateways - do you have 2 Internet connections?

 

Perhaps a proxy server (e.g. squid) could be configured to do this - I don't know, and cannot spare the time to find out at the moment...sorry.

 

I don't think that netfilter could do what you are asking - AFAIK you can't filter on hostnames.

 

Windows can have static routes set up - you may be able to do something there. Try typing route into a windows command line (I think that's the command)

 

Forgive the waffle - just thinking out loud :)

 

Chris

Link to comment
Share on other sites

Guest stuck_techy

sorry, i forgot to mention the areas highlighted in red i have no control over whatsoever.

 

The reason for the 2 gateways is thus: gateway1 connects my network to the internet, gateway2 is just a router with an adsl modem behind it which gives a physical link to my remote network.

 

Currently the route only works either to g1 or g2, it will not route to both at the same time. (this is only a quick fix anyway, i can not leave routing on this server hence why i am attempting linux).

 

the remote dns is the only way (security) of accessing hosts therefore, i had the win server with dns and forwarding to the remote dns. then used route to get to the resolved ip.

 

As i said before if i am better off starting with mandrake 10 full instead then that is what i will do. but i would still like any ideas as to whether it is possible or not.

 

i hope that helps clarify a few things.

:)

Link to comment
Share on other sites

Don't know if something like this will work:

 

Presumeably the address of www.host.com will always be 10.x.x.x, so you can do: route add -net 10.0.0.0/8 gw 192.168.0.2 to add a gateway address for the 10.0.0.0 network. You should even be able to do similar in windows with the old DOS route command - is it still there?

 

Then you need to be able to get the IP address from the nameserver - if the nameserver on 10.0.0.1 is fully functional - i.e. it can resolve anything, just use it as your main nameserver. If it only handles the network it is on, put it's address second in the list - when 'www.host.com' is not found (I assume it has a unique name not found anywhere on the Internet??) your PC will try 10.0.0.1 - bit slower, but it should work...

 

This is probably badly flawed somehow :)

 

Chris

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
 Share

×
×
  • Create New...