From: Jorge Davila <davila@nicaraguaopensource.com>
To: Yaniv Fine <yfine@jacada.com>, netfilter@lists.netfilter.org
Subject: Re: iptables port forwarding to tun0 device
Date: Sun, 10 Jun 2007 08:25:20 -0600 [thread overview]
Message-ID: <web-17954090@bk3.webmaillogin.com> (raw)
In-Reply-To: <OF00836A91.C83C2AC5-ONC22572F2.004ABBD7-C22572F2.004B9171@jacada.com>
Yaniv:
Since the tun device is created you can reference them as another network
interface and configure the iptables rules as normal.
Hope this help,
Jorge Davila.
On Wed, 6 Jun 2007 16:45:24 +0300
Yaniv Fine <yfine@jacada.com> wrote:
>
> Hi experts
>
> i have the following configuration
> eth0.10.90.20.3/24
> tun0=172.16.10.x/24
>
> eth0 configure as Wan interface
> eth1/tun0 are lan interface .
> tun0 network 172.16.10.200 => web server
> in side my tun0 there is a web server i need to manage for the outside
> world (eth0, it can also be restricted to specific ip address )
> i am trying to find a way using port forwarding to enable this .
> can some one please help me modify my correct iptables rules
>
>
>
>
> IPTABLES="/sbin/iptables"
> EXTIF="eth0"
> INTIF="eth1"
>
> #Flush all rules
> $IPTABLES -F
> $IPTABLES -F -t nat
> $IPTABLES -F -t mangle
>
> #Set default behaviour
> $IPTABLES -P INPUT DROP
> $IPTABLES -P FORWARD ACCEPT
> $IPTABLES -P OUTPUT ACCEPT
>
> #Allow related and established on all interfaces (input)
> $IPTABLES -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
>
> #Allow releated, established and ssh on $EXTIF. Reject everything else.
> $IPTABLES -A INPUT -i $EXTIF -p tcp -m tcp --dport 22 --syn -j ACCEPT
> #$IPTABLES -A INPUT -i $EXTIF -p tcp -m tcp --dport 80 --syn -j ACCEPT
> $IPTABLES -A INPUT -i $EXTIF -j REJECT
>
> #Allow related and established from $INTIF. Drop everything else.
> $IPTABLES -A INPUT -i $INTIF -j DROP
>
> #Allow http and https on other interfaces (input).
> #This is only needed if authentication server is on same server as chilli
> $IPTABLES -A INPUT -p tcp -m tcp --dport 80 --syn -j ACCEPT
> $IPTABLES -A INPUT -p tcp -m tcp --dport 443 --syn -j ACCEPT
>
> #Allow 3990 on other interfaces (input).
> $IPTABLES -A INPUT -p tcp -m tcp --dport 3990 --syn -j ACCEPT
>
> #Allow ICMP echo on other interfaces (input).
> $IPTABLES -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
>
> #Allow everything on loopback interface.
> $IPTABLES -A INPUT -i lo -j ACCEPT
>
> # Drop everything to and from $INTIF (forward)
> # This means that access points can only be managed from ChilliSpot
> $IPTABLES -A FORWARD -i $INTIF -j DROP
> $IPTABLES -A FORWARD -o $INTIF -j DROP
>
> #Enable NAT on output device
> $IPTABLES -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
>
>
> thank you !
>
>
>
Jorge Isaac Davila Lopez
Nicaragua Open Source
+505 430 5462
davila@nicaraguaopensource.com
next prev parent reply other threads:[~2007-06-10 14:25 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-06-06 13:45 iptables port forwarding to tun0 device Yaniv Fine
2007-06-10 14:25 ` Jorge Davila [this message]
2007-06-10 14:29 ` Yaniv Fine
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=web-17954090@bk3.webmaillogin.com \
--to=davila@nicaraguaopensource.com \
--cc=netfilter@lists.netfilter.org \
--cc=yfine@jacada.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.