From mboxrd@z Thu Jan 1 00:00:00 1970 From: Payal Rathod Subject: Re: dnatting Date: Mon, 11 Jul 2005 14:21:58 -0400 Message-ID: <20050711182158.GA31027@tranquility.scriptkitchen.com> References: <20050711151830.GA26670@tranquility.scriptkitchen.com> Mime-Version: 1.0 Return-path: Content-Disposition: inline In-Reply-To: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: Jan Engelhardt Cc: Netfilter ML On Mon, Jul 11, 2005 at 05:20:43PM +0200, Jan Engelhardt wrote: > > >Hi, > >I have a rule on my friend's broadband connection to redirect traffic > >from outside to an internal machine like, > > > >iptables -A PREROUTING -d 1.2.3.4 -p tcp -m tcp --dport 80 -j DNAT \ > >--to-destination 192.168.10.10:80 > > > >But she complained that people from inside the network cannot do > >http://1.2.3.4 in their browser and see the site. Is she correct? > >What is wrong with my rule because I can see the site from outside? > > The packet must pass the machine the DNAT rule is on to make the dnat > effective. > So what do I do exactly? With warm regards, -Payal