All of lore.kernel.org
 help / color / mirror / Atom feed
From: Raymond Leach <raymondl@knowledgefactory.co.za>
To: cc <cc@ns.kdtc.net>
Cc: Netfilter Mailing List <netfilter@lists.netfilter.org>
Subject: Re: local forwarding(?)
Date: 17 Jan 2003 13:38:43 +0200	[thread overview]
Message-ID: <1042803523.485.69.camel@rayw.knowledgefactory.co.za> (raw)
In-Reply-To: <200301171115.h0HBFJZC013763@ns.kdtc.net>

[-- Attachment #1: Type: text/plain, Size: 2952 bytes --]

On Fri, 2003-01-17 at 13:15, cc wrote:
> Hi,
> 
> I finally got the bridge working and so far, 
> things look ok.  
> 
> >From the outside, I can goto the website.  That's
> no problem.  The problem is for local machines
> going to http://www.mydomain.com/, the firewall
> doesn't seem to be redirecting it properly.
> LAN users have to use http://192.168.11.10/ to
> access the website instead of the www.mydomain.com.
> 
> I understand that the actual ip address skips
> the firewall and goes directly to the machine.
> >From my boss' point of view(totally ignorant
> that 192.168.11.10 = www.mydomain.com), he
> doesn't like that.  So I'm hoping that he
> can access (locally) www.mydomain.com.
> 
> So far my firewall script (the lines pertaining
> to the www port) is as follows:
> 
> $IPTABLES -t nat -A PREROUTING -p tcp -i eth0 x.x.x.x \
>       --dport 80 -j DNAT --to 192.168.10.11
> $IPTABLES -A FORWARD -p tcp -i eth0 -d 192.168.10.11 \
>       --dport 80 -j ACCEPT
> $IPTABLES -A FORWARD -p tcp -i eth0 --dport 80 -j DROP
> 
> (I'm not entirely sure about that last item.  It looks
> strangely invalid...but I could be wrong.  I don't
> even think I should have that there.. am I right?)
Depends on the default POLICY for your FORWARD chain. If the default
policy is to drop, then you don't need it.

> 
> If all my LAN ips are of the 192.168.10.0 host, 
> and the web server is 192.168.10.11, how do I
> get the LAN clients to go to www.mydomain.com and
> have the firewall redirect the packets to 192.168.10.11?
> 
Is the firewall the gateway to the internet for your users?

iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 80 -d
www.mydomain.com -j REDIRECT --to-destination 192.168.10.11:80

That should work (eth0 is your internal interface, right?) ...

Of course you also need the forwarding rules:

iptables -A FORWARD -p tcp --dport 80 -d 192.168.1.11 -j ACCEPT
iptables -A FORWARD -p tcp --sport 80 -s 192.168.1.11 -j ACCEPT

These are very wide open rules. You might want to add the -i and maybe
state checking...

> As you probably can figure out, I'm a little confused. 
> 
> Any help appreciated
> 
-- 
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
(  Raymond Leach                       )
 ) Knowledge Factory                  (
(                                      )
 ) Tel: +27 11 445 8100               (
(  Fax: +27 11 445 8101                )
 )                                    (
(  http://www.knowledgefactory.co.za/  )
 ) http://www.saptg.co.za/            (
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   o                                o
    o                              o
        .--.                  .--.
       | o_o|                |o_o |
       | \_:|                |:_/ |
      / /   \\              //   \ \
     ( |     |)            (|     | )
     /`\_   _/'\          /'\_   _/`\
     \___)=(___/          \___)=(___/

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2003-01-17 11:38 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-01-17 11:15 local forwarding(?) cc
2003-01-17 11:38 ` Raymond Leach [this message]
2003-01-17 11:50 ` Narendra Prabhu. B

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1042803523.485.69.camel@rayw.knowledgefactory.co.za \
    --to=raymondl@knowledgefactory.co.za \
    --cc=cc@ns.kdtc.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.