All of lore.kernel.org
 help / color / mirror / Atom feed
* iptables configuration help
@ 2004-11-05 15:41 Vijay Kumar
  2004-11-05 15:42 ` Jason Opperisano
  2004-11-05 15:45 ` John A. Sullivan III
  0 siblings, 2 replies; 3+ messages in thread
From: Vijay Kumar @ 2004-11-05 15:41 UTC (permalink / raw)
  To: netfilter

Hello,

I have a firewall with three nic ( external ip, DMZ ip, LAN ip ) 
I have added a subinterface on the external interface ( public ip with a public ip address ) 

There is 1 machine on the internal LAN and I want it to go out using the IP of the sub interface,
i.e access the internet using the exteral sub interface IP which I have added. 

I have done the following : 

iptables -t nat -I POSTROUTING -s 172.16.0.119 -o eth1:0 -j SNAT --to-source <external_ip> 

After adding this I also added the below mentioned rules : 

iptables -A INPUT -s 172.16.0.119 -d 0.0.0.0/0.0.0.0 -j ACCEPT 
iptables -I FORWARD -s 172.16.0.119 -j ACCEPT 

When I addded the rules iptables gave me an Warning stating :" Weird character in interface eth0:0, no ! : "

Where am I going wrong ? Are sub interface allowed in iptables ? 

What iptables rule should  add so that the LAN machine uses the subinterface to reach the internet ? 

What i need is something like static nat ?

Kindly help.

Vijay. 

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2004-11-05 15:45 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-11-05 15:41 iptables configuration help Vijay Kumar
2004-11-05 15:42 ` Jason Opperisano
2004-11-05 15:45 ` John A. Sullivan III

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.