Linux Netfilter discussions
 help / color / mirror / Atom feed
* mail server problem
@ 2003-11-10  9:48 Roberto Rossi
  2003-11-10  9:58 ` Antony Stone
  0 siblings, 1 reply; 6+ messages in thread
From: Roberto Rossi @ 2003-11-10  9:48 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 764 bytes --]

Hello all,

I've a range of 30 public internet addresses to manage starting, say, from 213.25.24.0 to 213.25.24.31 netmask of course 255.255.255.224.

My firewall (Red Hat 9.0, latest kernel) public IP is 213.25.24.30 the router address is 213.25.24.1 and the LAN network is 10.1.0.0/16.

I've an internal mail server, say, 10.1.1.2 which I would like to see from the outside as 213.25.24.3, one IP of my range.

Except DNS registration, what are the correct steps to make this possible?

I just set this rule on my firewall:
iptables -t nat -A PREROUTING -p tcp -i eth0 -d 213.25.24.3 --dport 25 -j DNAT --to 10.1.1.2:25

but I guess it's not enough because it's not working.

A help is really appreciated, thanks in advance.

Roberto - Italy    

[-- Attachment #2: Type: text/html, Size: 1884 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread
* RE: mail server problem
@ 2003-11-10 14:43 MOUDARIR Mohamed
  0 siblings, 0 replies; 6+ messages in thread
From: MOUDARIR Mohamed @ 2003-11-10 14:43 UTC (permalink / raw)
  To: Roberto Rossi, netfilter

[-- Attachment #1: Type: text/plain, Size: 1161 bytes --]

May be you should also add this rule :
iptables -A FORWARD -p TCP -i eth0 -o eth1 -d 10.1.1.2 --dport 25 -j allowed
eth1 is your NIC connected to your private LAN network is 10.1.0.0/16.

-----Message d'origine-----
De : Roberto Rossi [mailto:roberto.rossi@smc.it]
Envoyé : vendredi 7 novembre 2003 15:10
À : netfilter@lists.netfilter.org
Objet : mail server problem



Hello all,
 
I've a range of 30 public internet addresses to manage starting, say, from
213.25.24.0 to 213.25.24.31 netmask of course 255.255.255.224.
 
My firewall (Red Hat 9.0, latest kernel) public IP is 213.25.24.30 the
router address is 213.25.24.1 and the LAN network is 10.1.0.0/16.
 
I've an internal mail server, say, 10.1.1.2 which I would like to see from
the outside as 213.25.24.3, one IP of my range.
 
Except DNS registration, what are the correct steps to make this possible?
 
I just set this rule on my firewall:
iptables -t nat -A PREROUTING -p tcp -i eth0 -d 213.25.24.3 --dport 25 -j
DNAT --to 10.1.1.2:25

but I guess it's not enough because it's not working.
 
A help is really appreciated, thanks in advance.
 
Roberto - Italy    


[-- Attachment #2: Type: text/html, Size: 2858 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread
* mail server problem
@ 2003-11-07 15:10 Roberto Rossi
  0 siblings, 0 replies; 6+ messages in thread
From: Roberto Rossi @ 2003-11-07 15:10 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 764 bytes --]

Hello all,

I've a range of 30 public internet addresses to manage starting, say, from 213.25.24.0 to 213.25.24.31 netmask of course 255.255.255.224.

My firewall (Red Hat 9.0, latest kernel) public IP is 213.25.24.30 the router address is 213.25.24.1 and the LAN network is 10.1.0.0/16.

I've an internal mail server, say, 10.1.1.2 which I would like to see from the outside as 213.25.24.3, one IP of my range.

Except DNS registration, what are the correct steps to make this possible?

I just set this rule on my firewall:
iptables -t nat -A PREROUTING -p tcp -i eth0 -d 213.25.24.3 --dport 25 -j DNAT --to 10.1.1.2:25

but I guess it's not enough because it's not working.

A help is really appreciated, thanks in advance.

Roberto - Italy    

[-- Attachment #2: Type: text/html, Size: 1884 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-11-10 14:43 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-10  9:48 mail server problem Roberto Rossi
2003-11-10  9:58 ` Antony Stone
2003-11-10 10:15   ` netfilter
2003-11-10 10:25     ` Antony Stone
  -- strict thread matches above, loose matches on Subject: below --
2003-11-10 14:43 MOUDARIR Mohamed
2003-11-07 15:10 Roberto Rossi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox