From: "Danila Octavian" <octavian@service.agress.ro>
To: Bruno Negrao <vpopmail@engepel.com.br>
Cc: netfilter@lists.netfilter.org
Subject: Re: Hostname with DNAT ? {OK}
Date: Wed, 28 Jul 2004 09:18:14 +0300 [thread overview]
Message-ID: <016b01c4746a$be09df90$da0da8c0@pisic> (raw)
In-Reply-To: 011401c473e4$5db3d1e0$5100a8c0@egp
[-- Attachment #1: Type: text/plain, Size: 3446 bytes --]
Hi Danila, there are some error in your rules, first i'll correct them, then i'll tell you about using names
I know the rules were wrong ... i was in a rush ... u are right, but i was trying to do something else. I will give my setup just to see what i was asking :
internet ---> public ip eth0 eth1 private ip --> mail.server1.com private ip eth0 eth1 private ip ---> lan
--> mail.server2.com private ip eth0 eth1 private ip ---> lan
--> mail.server3.com private ip eth0 eth1 private ip ---> lan
The problem is that i have 3 names on the same public IP and i want to send mail traffic to those servers which have private ips.
I don't want to use smtp on the router with public ip , just redirrect name based to the machines behind accordingly.
thank you very much for your help,
Danila Octavian
----- Original Message -----
From: Danila Octavian
To: netfilter@lists.netfilter.org
Sent: Monday, July 26, 2004 11:40 AM
Subject: Hostname with DNAT ? {OK}
hello,
I was wondering if you can guide me how to deal with my situation :
I want to do something like :
read carefully this rule:
$IPTABLES -A PREROUTING -t nat -i eth0 -p tcp -d mail.server1.com --dport 25 -j DNAT --to 192.168.14.254:25
From now on, when the packet arrives the FORWARD chain of the filter table, it is not destinated to mail.server1.com anymore, since you have just changed its destination IP with the rule above. it is destined to 192.168.14.254.
the '-d IP' in the rule bellow is wrong:
$IPTABLES -A FORWARD -i eth0 -p tcp -d mail1.server.com --dport 25 -j ACCEPT
You should write instead:
$IPTABLES -A FORWARD -i eth0 -p tcp -d 192.168.14.254 --dport 25 -j ACCEPT
did you got it?
This applies for all these rules bellow:
$IPTABLES -A PREROUTING -t nat -i eth0 -p tcp -d mail.server2.com --dport 25 -j DNAT --to 192.168.14.251:25
$IPTABLES -A FORWARD -i eth0 -p tcp -d mail.server2.com(wrong) --dport 25 -j ACCEPT
$IPTABLES -A PREROUTING -t nat -i eth0 -p tcp -d server3.com --dport 25 -j DNAT --to 192.168.14.253:25
$IPTABLES -A FORWARD -i eth0 -p tcp -d server3.com(wrong) --dport 25 -j ACCEPT
$IPTABLES -A PREROUTING -t nat -i eth0 -p tcp -d mail.server3.com --dport 25 -j DNAT --to 192.168.14.253:25
$IPTABLES -A FORWARD -i eth0 -p tcp -d mail.server3.com(wrong) --dport 25 -j ACCEPT
Is posibble to use names instead of IP like in my situation ?
Yes, it is *possible*. It depends of whether your firewall can access the DNS server when it is loading those rules.
In my firewall, when it is loading the PREROUTING rules, it didn't load the INPUT and OUTPUT rules yet, so it is not permitted to send nor receive any packet, so it can't contact the DNS server to resolve names.
In my firewall I just load the FORWARD rules after i have loaded the INPUT and OUTPUT chains, so my firewall already can access the DNS server.
hope it helps,
bruno
--
This message has been scanned for viruses and
dangerous content, and is believed to be clean.
Service.Agress.Ro E-Mail Scanning Service.
--
This message has been scanned for viruses and
dangerous content, and is believed to be clean.
Service.Agress.Ro E-Mail Scanning Service
[-- Attachment #2: Type: text/html, Size: 7827 bytes --]
next prev parent reply other threads:[~2004-07-28 6:18 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-07-26 14:40 Hostname with DNAT ? {OK} Danila Octavian
2004-07-27 14:16 ` Bruno Negrao
2004-07-28 6:18 ` Danila Octavian [this message]
-- strict thread matches above, loose matches on Subject: below --
2004-07-26 15:30 Jason Opperisano
2004-07-27 7:54 ` Danila Octavian
2004-07-27 8:44 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='016b01c4746a$be09df90$da0da8c0@pisic' \
--to=octavian@service.agress.ro \
--cc=netfilter@lists.netfilter.org \
--cc=vpopmail@engepel.com.br \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox