All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: DNATing back to the same network
@ 2005-02-09  8:43 Ian! D. Allen
  0 siblings, 0 replies; 8+ messages in thread
From: Ian! D. Allen @ 2005-02-09  8:43 UTC (permalink / raw)
  To: netfilter

>However, when a local users tries to connect to the public IP and DNATed
>port, the connection fails. Which is basically logical as the server
>receives a packet with the source IP of the actual user and it answeres
>directly to that IP.  Is it possible to change netfilter behaviour? Any
>other work-around for that?

As Samuel noted, that is described here:

    http://www.netfilter.org/documentation/HOWTO/NAT-HOWTO-10.html

and I elaborate on it here:

    http://idallen.com/dnat.txt

-- 
-IAN!  Ian! D. Allen   Ottawa, Ontario, Canada
       EMail: idallen@idallen.ca   WWW: http://www.idallen.com/
       College professor (Linux) via: http://teaching.idallen.com/
       Support free and open public digital rights:  http://eff.org/


^ permalink raw reply	[flat|nested] 8+ messages in thread
* DNATing back to the same network
@ 2005-01-13 14:42 danci
  2005-01-13 15:35 ` Charlie Brady
  2005-01-13 15:56 ` Samuel Jean
  0 siblings, 2 replies; 8+ messages in thread
From: danci @ 2005-01-13 14:42 UTC (permalink / raw)
  To: netfilter

Hi!

I have a firewall with a number of DNAT rules for various ports/hosts. It 
would be good if local users could use the same DNAT's. However, as it 
seems this doesn't work.

My firewall has a public IP. Some ports on this IP are DNATed to different 
hosts on the local network. DNAT works for users that connect from the 
internet.

However, when a local users tries to connect to the public IP and DNATed 
port, the connection fails. Which is basically logical as the server 
receives a packet with the source IP of the actual user and it answeres 
directly to that IP.

Is it possible to change netfilter behaviour? Any other work-around for 
that?

Thanks, Danilo


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2005-02-17 17:31 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <20050113165624.C0BFA5F67@mail.microtechniques.com>
2005-01-13 19:26 ` DNATing back to the same network Don Hughes
2005-01-13 20:17   ` danci
2005-01-13 22:49     ` Charlie Brady
2005-02-09  8:43 Ian! D. Allen
  -- strict thread matches above, loose matches on Subject: below --
2005-01-13 14:42 danci
2005-01-13 15:35 ` Charlie Brady
2005-01-13 15:56 ` Samuel Jean
2005-02-17 17:31   ` Mohammad Khan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.