I sent this query to the debian.user group, but couldn't find any help

I'm installing the debian/testing cipe package.  I'm using kernel version
2.4.17-rc1, which is 2.4.16 pre-patched for 17.  The kernel is configured
for iptables support on two identical masquerading firewall machines.  I
installed the cipe package, compiled, and installed the resulting
cipe*.deb package.  All's well, so far:

Destination     Gateway         Genmask         Flags Metric Ref    Use
Iface   *      UH    0      0        0 cipcb0     *        U     0      0        0 eth1 *        U     0      0        0 eth0
default         gw.machine1         UG    0      0        0 eth0

Now, I need to insert the appropriate chains so that packets can pass
between the two private LANs.  I have read through "The Linux
Cipe+Masquerading mini-HOWTO", and I see how the chains are inserted via
the sample ip-up script for kernel 2.1/2.2 with ipchains.  But, before I
try to translate all their ipchains rules into iptables rules ....

Is there anyone out there that has created cipe ip-up/down scripts that
will insert _iptables_ chains that will bring up the cipcb0 interfaces

My setup is like this:

LAN-1 ( <==>
        FW-1 <===>
                Internet <==>
                        FW-2 <==> LAN-2 (


1. CIPE, IPTABLES, Masquerading

Can someone please help with how to configure iptables with a cipe link
connecting two ethernet networks.  The following is a rough diagram of how
the networks are configured Ethernet Network
|| - Redhat 7.2 Linux Server
| Dial up link real IP, CIPE IP
| Dial up link real IP, CIPE IP - Redhat 7.2 Linux Server
|| Ethernet Network

Basically I want all computers on to be able to see all
computers on and vice versa.  Also, the 192.168.x.0 computers
need to be able to have masqueraded internet access.

I have managed to get CIPE up and running and and
can see each other just nicely.  I have managed to get routing set up
properly, and with no iptables set up at all, both networks communicate
together just nicely.  The trouble is though, I then don't have any
masqueraded internet access.  As soon as I turn on iptables for
masquerading, and can still see each other, but none
of the network computers can see the other network.  What do i need to do to
my iptables to get masquerading working AND have the networks be able to see
each other properly?

currently my /etc/sysconfig/iptables file is:
# Generated by iptables-save v1.2.3 on Tue Mar 19 17:12:34 2002
:PREROUTING ACCEPT [10168:715722]
:OUTPUT ACCEPT [1540:144302]
# Completed on Tue Mar 19 17:12:34 2002
# Generated by iptables-save v1.2.3 on Tue Mar 19 17:12:34 2002
:INPUT ACCEPT [287217:51887269]
:OUTPUT ACCEPT [335706:261610800]

I tried adding the following to the output section under *nat but it made no

