All of lore.kernel.org
 help / color / mirror / Atom feed
* DNAT not working
@ 2006-12-22 15:03 Balazs Fulop
  2006-12-22 20:38 ` Grant Taylor
  0 siblings, 1 reply; 21+ messages in thread
From: Balazs Fulop @ 2006-12-22 15:03 UTC (permalink / raw)
  To: netfilter

Dear List!

I have the following setup:
eth0 (WAN, with multiple alias IPs), eth1 (LAN1), eth2 (LAN2), eth3 (LAN3)

I would like to setup DNAT, in order to achieve the following:
packets coming from eth0 to a certain IP and tcp port get NATed to an IP 
and port for a machine on one of the LAN subnets

I have read the relevant HOWTO and made the following setup:
# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use 
Iface
aaa.bbb.ccc.ddd   0.0.0.0         255.255.255.248 U     0      0        
0 eth0
192.168.5.0     0.0.0.0         255.255.255.0   U     0      0        0 eth3
192.168.4.0     0.0.0.0         255.255.255.0   U     0      0        0 eth2
192.168.3.0     0.0.0.0         255.255.255.0   U     0      0        0 eth1
0.0.0.0         aaa.bbb.ccc.eee   0.0.0.0         UG    0      0        
0 eth0
# cat /var/lib/iptables/testing
# Generated by iptables-save v1.3.5 on Fri Dec 22 14:23:36 2006
*mangle
:PREROUTING ACCEPT [1804:164934]
:INPUT ACCEPT [1576:145710]
:FORWARD ACCEPT [208:12864]
:OUTPUT ACCEPT [988:111965]
:POSTROUTING ACCEPT [1239:130436]
COMMIT
# Completed on Fri Dec 22 14:23:36 2006
# Generated by iptables-save v1.3.5 on Fri Dec 22 14:23:36 2006
*nat
:PREROUTING ACCEPT [58:10171]
:POSTROUTING ACCEPT [13:1459]
:OUTPUT ACCEPT [13:1459]
-A PREROUTING -d aaa.bbb.ccc.fff -i eth0 -p tcp -m tcp --dport 25 -j 
DNAT --to-destination 192.168.3.1
-A PREROUTING -j LOG --log-prefix "PREROUTING: " --log-level 7
COMMIT
# Completed on Fri Dec 22 14:23:36 2006
# Generated by iptables-save v1.3.5 on Fri Dec 22 14:23:36 2006
*filter
:INPUT ACCEPT [1576:145710]
:FORWARD ACCEPT [208:12864]
:OUTPUT ACCEPT [988:111965]
-A FORWARD -d 192.168.3.1 -i eth0 -o eth1 -p tcp -m tcp --dport 25 -j 
ACCEPT
-A FORWARD -j LOG --log-prefix "FORWARD: " --log-level 7
COMMIT
# Completed on Fri Dec 22 14:23:36 2006

If I telnet 192.168.3.1 25 on the firewall, an SMTP session starts. If I 
telnet from outside (coming on eth0), it waits until timeout. I just 
can't figure out why it is not working. At last I removed all the IP 
aliases, and it didn't work that way either. There is nothing relevant 
in /var/log/syslog. I have 1 in /proc/sys/net/ipv4/ip_forward.

Please help. Thanks in advance.

Yours sincerely,
    Fülöp Balázs



^ permalink raw reply	[flat|nested] 21+ messages in thread
* DNAT not working
@ 2007-04-18 16:26 Payal Rathod
  2007-04-18 17:34 ` Martijn Lievaart
  0 siblings, 1 reply; 21+ messages in thread
From: Payal Rathod @ 2007-04-18 16:26 UTC (permalink / raw)
  To: netfilter

Hi,
My gateway server is Ubuntu 6.06.1 LTS, iptables v1.3.3.  By ifconfig I 
have added one more ip say 1.2.3.4 (eth0:1). iptables-save gives me the 
output at,
http://pastebin.ca/446625

# cat /proc/sys/net/ipv4/ip_forward
1


But when I connect to 1.2.3.4 port 25,  instead of redirecting me to 
10.10.200.2 it connects me to port 25 of the gateway machine. I am 
totally confused, can anyone help me out please?

With warm regards,
-Payal


^ permalink raw reply	[flat|nested] 21+ messages in thread
* DNAT Not working
@ 2004-07-12 15:12 Nicolas Ross
  2004-07-12 15:59 ` Antony Stone
  0 siblings, 1 reply; 21+ messages in thread
From: Nicolas Ross @ 2004-07-12 15:12 UTC (permalink / raw)
  To: netfilter

Hi all !

I a have a fw box running RH 7.3.

Here's part of my nat table :

-A PREROUTING  -p tcp -m tcp -s 172.16.190.0/255.255.255.0 --dport 80 -j
REDIRECT --to-ports 8080
-A POSTROUTING -p tcp -m tcp -s 172.16.190.0/255.255.255.0 ! --dport 80 -o
eth0 -j SNAT --to-source 1.1.1.1
-A POSTROUTING -p udp -m udp -s 172.16.190.0/255.255.255.0 -o eth0 -j
SNAT --to-source 1.1.1.1
-A POSTROUTING -p icmp -m icmp -s 172.16.190.0/255.255.255.0 -o eth0 -j
SNAT --to-source 1.1.1.1

-A PREROUTING -p tcp -m tcp -i eth0 -d 1.1.2.1 --dport 80 -j
DNAT --to-destination 172.16.190.5
-A PREROUTING -p tcp -m tcp -i eth0 -d 1.1.2.1 --dport 9287 -j
DNAT --to-destination 172.16.190.5
-A PREROUTING -i eth0 -d 1.1.2.2 -j DNAT --to-destination 172.16.190.7
-A PREROUTING -p tcp -m tcp -i eth0 -d 1.1.2.3 --dport 5003 -j
DNAT --to-destination 172.16.190.143


Part of my filer table :

-A FORWARD -i eth0 -o eth2 -p tcp -m tcp -d 172.16.190.5 --dport 80 -j
ACCEPT
-A FORWARD -i eth0 -o eth2 -p tcp -m tcp -d 172.16.190.5 --dport 9287 -j
ACCEPT
-A FORWARD -i eth0 -o eth2 -d 172.16.190.7 -j ACCEPT
-A FORWARD -i eth0 -o eth2 -p tcp -m tcp -d 172.16.190.143 --dport 5003 -j
ACCEPT

There are other things in it, and my last FORWARD line is a LOG one.

1.1.1.1 (fake ip) is the ext. ip of the box (eth0)
1.1.2.x are ips routed by the box.
172.16.190.x are internal ips (eth1)


DNAT to 172.16.190.5, port 80 works fine.
DNAT to 172.16.190.143, port 5003 is not.

In /proc/net/ip_conntrack, I see :

tcp      6 118 SYN_SENT src=x.x.x.x dst=x.x.x.x sport=49502 dport=5003
[UNREPLIED] src=172.16.190.143 dst=x.x.x.x sport=5003 dport=49502 use=1

With iptables -nvL, I see packet counter rising for the 2 rules concerning
port 5003

On the 172.16.190.143 box, wich is a mac os x box, with netstat -an | grep
5003, I see :

tcp4       0      0  172.16.190.143.5003    x.x.x.x.62382          SYN_RCVD
tcp4       0      0  172.16.190.143.5003    172.16.190.153.49342
ESTABLISHED
tcp4       0      0  127.0.0.1.5003         127.0.0.1.49184
ESTABLISHED
tcp4       0      0  127.0.0.1.49184        127.0.0.1.5003
ESTABLISHED
tcp4       0      0  *.5003                 *.*                    LISTEN

I see nothing being logued.

I tried removing port selection as in :

-A PREROUTING -i eth0 -d 1.1.2.3 -j DNAT --to-destination 172.16.190.143
-A FORWARD -i eth0 -o eth2 -d 172.16.190.143 -j ACCEPT

Still the same thing.

What am I missing ?



^ permalink raw reply	[flat|nested] 21+ messages in thread
* DNAT not working
@ 2004-03-18 20:26 Stuart Lamble
  2004-03-18 20:49 ` John A. Sullivan III
  2004-03-18 20:50 ` Antony Stone
  0 siblings, 2 replies; 21+ messages in thread
From: Stuart Lamble @ 2004-03-18 20:26 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 728 bytes --]

Hello netfilter lists
 
Can any one help me here. I have the following rule...
 
iptables -t nat -A PREROUTING -i ppp0 -p tcp -d $FW-EXT-IP --dport 22 -j
DNAT --to 192.168.100.6:22
 
Simply put I want to allow ssh from the internet to a server on my LAN,
192.168.100.6
My FORWARD rule is default accept.
 
I understand that a packet comes into the firewall on an interface and
then gets PREROUTED as above the gets passed to FORWARD = accept then to
the destination???
 
Why is it not working? Do i need to do any special kernel, modprobe
things?
Thanks
Stu

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.631 / Virus Database: 404 - Release Date: 3/17/2004
 

[-- Attachment #2: Type: text/html, Size: 2244 bytes --]

^ permalink raw reply	[flat|nested] 21+ messages in thread
[parent not found: <20031224052809.18657.42710.Mailman@netfilter-sponsored-by.noris.net>]

end of thread, other threads:[~2007-04-19 17:18 UTC | newest]

Thread overview: 21+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-12-22 15:03 DNAT not working Balazs Fulop
2006-12-22 20:38 ` Grant Taylor
2006-12-22 21:14   ` Pascal Hambourg
2006-12-26 20:54     ` Balazs Fulop
  -- strict thread matches above, loose matches on Subject: below --
2007-04-18 16:26 Payal Rathod
2007-04-18 17:34 ` Martijn Lievaart
2007-04-19  3:31   ` Payal Rathod
2007-04-19 11:15     ` Gáspár Lajos
2007-04-19 17:18       ` Payal Rathod
2004-07-12 15:12 DNAT Not working Nicolas Ross
2004-07-12 15:59 ` Antony Stone
2004-07-12 16:13   ` Nicolas Ross
2004-07-12 16:33     ` Antony Stone
2004-03-18 20:26 DNAT not working Stuart Lamble
2004-03-18 20:49 ` John A. Sullivan III
2004-03-18 21:58   ` Antony Stone
2004-03-18 20:50 ` Antony Stone
2004-03-20 17:47   ` Stuart Lamble
     [not found] <20031224052809.18657.42710.Mailman@netfilter-sponsored-by.noris.net>
2003-12-24 10:24 ` DNAT NOT WORKING madhav bhasin
2003-12-24 10:33   ` Antony Stone
2003-12-25 18:31   ` Thomas Scheffczyk

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.