Koozali.org: home of the SME Server

Multiple IP's on one SME server

Hardijs

Re: Multiple IP's on one SME server
« Reply #15 on: August 05, 2003, 02:53:06 AM »
good read for this (and straighforward one) is at

http://mirror.contribs.org/smeserver/contribs/btalcott/howto/extraip.html

still the last question has not been answered - no www works

also by going all the various permutations I saw a strange thing - if the foreigh IP is made "local" from web panel the all works - otherwise it does not work except for ping

Guck Puppy

Re: Multiple IP's on one SME server
« Reply #16 on: August 05, 2003, 04:09:29 AM »
http://mirror.contribs.org/smeserver/contribs/btalcott/howto/extraiprules.html

This page will (Hey Bill, how's it going? Any skeleton of hints?) detail what changes need to be made to your firewall to allow the additional IP addresses to be used.

Hardijs wrote:
> also by going all the various permutations I saw a strange
> thing - if the foreigh IP is made "local" from web panel the
> all works - otherwise it does not work except for ping

This sounds as if you've just poked a big hole in your firewall. I hope I am mistaken.

G

Hardijs

how to templatize?
« Reply #17 on: August 05, 2003, 04:10:37 AM »
well I got it working by adding the subnet mask say "/30" to all[/most] occurances of "$OUTERNET" in the /etc/rc.d/init.d/masq
then
/etc/rc.d/init.d/masq restart

and it worked....

- ie all rules now work equaly for each of your/my external ip's
the nic/driver does know what to listen "from the ifconfig"

no need to change httpd.conf as it already listens to 0.0.0.0 which is prefiltered by masq - or so I understand.

I do not see a way to make a clean template withour rewriting the current system

Any ideas?

Hardijs

Re: how to templatize?
« Reply #18 on: August 05, 2003, 04:16:28 AM »
> > thing - if the foreigh IP is made "local" from web panel the
> > all works - otherwise it does not work except for ping
 
> This sounds as if you've just poked a big hole in your firewall. I hope I am mistaken.

not so  big as the not local subnet  ip addr that got "localised" was said to be "local" by me using the "Local networks " web panel - and I have am sure what is at the other end (just another esmith server)  no other ip's worked so ....