    Date: Sat, 04 Sep 2004 18:04:24 +0700

    Alex Harsch wrote:
    > riviereg wrote:
    >>Dear all linux networking,
    >>I try to set up a route to my ISP:
    >>my network is connected to the router on eth0
    >>my ISP is on link eth2 on my router (GNU/Debian sarge, kernel 2.6.8, I
    >>try with 2.6.7 same problem).
    >>my external IP is
    >>my gateway is (this is my modem, with a real IP address)
    >>I try to route my internal IP to this ISP
    >>my route is configure like this:
    >># ADSL line
    >>ip route flush table 5
    >>ip route add table 5 default via src dev eth2
    >>ip rule add fwmark 5 table 5
    >>my Nat is like this
    >>iptables -t mangle -A PREROUTING -s -j MARK --set-mark 5
    >>iptables -t nat -A POSTROUTING -o eth2 -s -j SNAT --to
    >>All is ok, I can access to my modem ( from, I can also
    >>access to internet on this modem (there is a web site on the modem).
    >>But when I try to access to Internet from, I can "find" sites
    >>but I receive nothing, all my ping are lost. This problem drive me crasy
    >>I think I send packets but there is a kind of incoming reply routing
    >>problem. All other IP's from my internal network can connect with the
    >>default gateway on my first ISP (eth1).
    >>Thank you for Help me on this,
    > Bon Jour Guillaume,
    > I think, you have a couple of problems here. First of all, you default
    > gateway should not be the modem, but your interface pppx.
    > Additionally, I think you have not configured your firewall to allow
    > incoming related/acknowledged packets.

    Thank you for this Alex,

    I fact I have a modem gateway with an assigned real IP Address,

    Internal Network ----| Linux box |-----| Modem gateway |----
                                            | Computer x |

    I aslo try to connect directly a computer (x) to the Modem gateway,
    with this modem as gateway and another real IP address provided by
    my ISP. From computer X I can access to Internet, no problem

    How to configure my firewall to allow incoming related/ackowledged
    packets ? I think my problem is something like this.

    Thank you very much for help,

