Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 22 Dec 2003 23:09:59 +0000
From:      Josh Paetzel <friar_josh@tcbug.org>
To:        "Jason C. Wells" <jcw@highperformance.net>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Routing to External IPs from Internal IPs
Message-ID:  <20031222230959.GH32419@ns1.tcbug.org>
In-Reply-To: <Pine.BSF.4.44.0312221754500.11773-100000@s1.stradamotorsports.com>
References:  <Pine.BSF.4.44.0312221754500.11773-100000@s1.stradamotorsports.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, Dec 22, 2003 at 06:07:24PM -0800, Jason C. Wells wrote:
> I would like to be able to set the DNS settings for my internal network to
> 209.20.215.30 and 209.20.215.31.  The internal network is addressed as
> 192.168.1/24.
> 
> How can I route from the internal addresses, through the internal
> interface of the firewall, to the external interface of the firewall, back
> through the port address translation to my internal nameservers?
> 
> If this question is too arcane, please refer me to the correct
> documentation.  I don't even know where to start.  Routing has always just
> magically worked on FreeBSD.  I would think it would be possible to add
> some sort of manual route to the routing tables, but what do I know.
> 
> The idea is to allow roamers to roam and never have to change any of their
> configuration settings, namely their DNS settings.
> 
> Split DNS obviously can handle all other settings such as mail, time, web
> and so forth.  Handling the DNS settings themselves, which are by IP
> address, proves more difficult.
> 
> Thanks,
> Jason C. Wells
> 

I'm not entirely sure I understand exactly what you are asking, but in answer 
to one of your questions, yes, you can add manual routes to the routing tables 
with the route command.  Whether this is what you want to do or not is another 
issue altoghter.

You may wish to setup a /30 subnet if you have a block of IPs to work with and 
then use nat to push them through your router.  

As far as roamers needing to change their DNS settings, I roam all over the 
place and use the same DNS servers all the time.  Perhaps all you need is 
someone to run slave DNS servers for you...you could easily forward port 53 
tcp/udp through nat to your internal nameservers.

HTH,
Josh Paetzel



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20031222230959.GH32419>