Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

2 ISP's DNAT into a common MASQed Server

ASL Beta 3.02 with 3 NIC's

eth0 - intLAN (Internal LAN)
eth1 - intDTI (SDSL ISP provider)
eth2 - intCHARTER (Cable ISP provider)

Default route of ASL box is eth1.

eth1
    \
     >eth0 10.0.0.139
    /
eth2

I have a server on the Internal LAN (10.0.0.139) which I would like to DNAT in from both eth1 and 
eth2.  

I can successfully connect with eth2's IP and contact 10.0.0.139.  However when I connect with eth1's IP, the live log states "IP Spoofing..."

12:19:49 [originating IP]4577  ->  [intDTI's IP eth1]21 TCP IP SPOOFING
SRC HW 00:80:ad:80:1f:81:00
DST HW 20:6f:11  5:21:08:00

Thanks
Jake


This thread was automatically locked due to age.