Linux Netfilter discussions
 help / color / mirror / Atom feed
* Port forwarding across two firewalls
@ 2004-05-06 20:36 R D
  0 siblings, 0 replies; 3+ messages in thread
From: R D @ 2004-05-06 20:36 UTC (permalink / raw)
  To: netfilter


Hi all,

I have a static IP (10.2.1.15) on which I need to have both TCP and UDP
ports 5000 appearing to be external! The subnet I'm on has a
firewall(Debian)
with an int IP 10.2.1.1 & ext 10.1.1.77 with gw 10.2.1.1 obviously. The
second firewall/router is a US Robotics ADSL Modem/Router with int IP
10.1.1.1
& ext 1.2.3.4.

When I lived in a house with just a Debian firewall and nothing configured
on
the modem the following worked:

iptables -A FORWARD -p udp -d 10.2.1.15 --dport 5000 -j ACCEPT
iptables -A PREROUTING -t nat -p udp -d fw-ext --dport 5000 -j DNAT --to
10.2.1.15:5000

iptables -A FORWARD -p tcp -d 10.2.1.15 --dport 5000 -j ACCEPT
iptables -A PREROUTING -t nat -p tcp -d fw-ext --dport 5000 -j DNAT --to
10.2.1.15:5000

I've tried the same commands with fw-ext=10.1.1.77 and setting a 'port range
mapping' on
the modem 10.1.1.77:5000-1.2.3.4:5000 for both UDP/TCP, but to no avail!

Any gurus out there that can help/explain!?


Many thanks,
R




^ permalink raw reply	[flat|nested] 3+ messages in thread
* Port forwarding across two firewalls
@ 2004-05-10 15:00 R D
  2004-05-11  8:33 ` Antony Stone
  0 siblings, 1 reply; 3+ messages in thread
From: R D @ 2004-05-10 15:00 UTC (permalink / raw)
  To: netfilter


Hi all,

I sent this before but got no reply...is there nobody out there that can
help
 me!?

I have a static IP (10.2.1.15) on which I need to have both TCP and UDP
ports 5000 appearing to be external! The subnet I'm on has a
firewall(Debian) with an int IP 10.2.1.1 & ext 10.1.1.77 with gw 10.2.1.1
obviously. The second firewall/router is a US Robotics ADSL
Modem/Router with int IP 10.1.1.1 & ext 1.2.3.4.

When I lived in a house with just a Debian firewall and nothing configured
on the modem the following worked:

iptables -A FORWARD -p udp -d 10.2.1.15 --dport 5000 -j ACCEPT
iptables -A PREROUTING -t nat -p udp -d fw-ext --dport 5000 -j DNAT --to
10.2.1.15:5000

iptables -A FORWARD -p tcp -d 10.2.1.15 --dport 5000 -j ACCEPT
iptables -A PREROUTING -t nat -p tcp -d fw-ext --dport 5000 -j DNAT --to
10.2.1.15:5000

I've tried the same commands with fw-ext=10.1.1.77 and setting a 'port range
mapping' on the modem 10.1.1.77:5000-1.2.3.4:5000 for both UDP/TCP, but to
no avail!

Any gurus out there that can help/explain!?


Many thanks,
R



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2004-05-11  8:33 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-05-06 20:36 Port forwarding across two firewalls R D
  -- strict thread matches above, loose matches on Subject: below --
2004-05-10 15:00 R D
2004-05-11  8:33 ` Antony Stone

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox