Linux Netfilter discussions
 help / color / mirror / Atom feed
* binding nntp to one interface
@ 2002-09-12  7:05 Rasmus Reinholdt Nielsen
  2002-09-12  9:15 ` Anders Fugmann
                   ` (2 more replies)
  0 siblings, 3 replies; 17+ messages in thread
From: Rasmus Reinholdt Nielsen @ 2002-09-12  7:05 UTC (permalink / raw)
  To: netfilter

Hi

I have two different internet connections, to two different ISP's, set up 
as load balancing.

My problem is that both my isp's have ip restricted their newsservers, so I 
need to bind all outgoing trafic on port 119 to a specific interface or ip. 
Anybody knows how to do this?

I have tried using redirect but it didn't work

iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 119 -j REDIRECT --to 
<wan-ip>

and I get an error of "Invalid argument" on this SNAT rule

iptables -t nat -A PREROUTING -p tcp -i eth0 --dport 119 -j SNAT --to <wan-ip>

hope somebody knows haw to do this.

Thanks

/Rasmus



^ permalink raw reply	[flat|nested] 17+ messages in thread
* iptables newbie
@ 2003-09-11 13:41 ads nat
  2003-09-11 14:28 ` Pascal Vilarem
  0 siblings, 1 reply; 17+ messages in thread
From: ads nat @ 2003-09-11 13:41 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 1235 bytes --]

Hi,
I have Linux REDHAT 8.0 server. Iptables are installed while installing Linux 8.0. version 1.2.6a
 
I am getting following error.
 
[root@xyz root]# /etc/init.d/iptables restart
Flushing all current rules and user defined chains:        [  OK  ]
Clearing all current rules and user defined chains:        [  OK  ]
Applying iptables firewall rules: iptables-restore v1.2.6a: Unknown arg `--dport'
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
                                                           [FAILED]
 
In iptables file i have used  :
*filter
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 0:1023 --syn -j REJECT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 2049 --syn -j REJECT
-A RH-Lokkit-0-50-INPUT -p udp -m udp --dport 0:1023 -j REJECT
-A RH-Lokkit-0-50-INPUT -p udp -m udp --dport 2049 -j REJECT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 6000:6009 --syn -j REJECT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 7100 --syn -j REJECT
COMMIT
*nat 
-A PREROUTING -p TCP --dport 80 -j REDIRECT --to-port 3128
COMMIT
 
Do i have to install any additional module.
Thanks

 


---------------------------------
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software

[-- Attachment #2: Type: text/html, Size: 1935 bytes --]

^ permalink raw reply	[flat|nested] 17+ messages in thread
* iptables newbie
@ 2003-12-27 13:31 Johan Cimen
  2003-12-27 14:50 ` John A. Sullivan III
  2003-12-27 21:26 ` Johan Cimen
  0 siblings, 2 replies; 17+ messages in thread
From: Johan Cimen @ 2003-12-27 13:31 UTC (permalink / raw)
  To: netfilter

Hi!

I am an iptables newbie and this is what I want do do with iptables:
1. I want to ulog incomming packets at PREROUTING, incomming at specific
ports with UDP protocol.
2. I am going to generate UDP packets from my local station, from specific
ports.
3. I want to set TOS and TTL fields of my packets matching specific ports
at OUTPORT or POSTROUTING.

Problem that I have is:
1. I cannot use:
   iptables -t mangle -A OUTPUT -o $IFACE -p UDP --dport 7001 -j TOS
--set-tos 0x10
   Using iptables -L shows nothing under OUTPUT headline.
   I cannot use tables at all.
2. I cannot use (just an example, nothing to do with what i want to do):
   iptables -A POSTROUTING -o $IFACE -p UDP --dport 7001
   iptables says: No chain/target/match by that name
   Above iptable command works for INPUT, FORWARD and OUTPUT chains.

Question is:
1. Have I missed something in my kernel configurations?
2. Have I missed something in building chains and targets?
3. I need help!

-Johan-


This is a part of my kernel konfigurations:
# Loadable module support

CONFIG_MODULES=y
CONFIG_MODVERSIONS=y
CONFIG_KMOD=y

# Networking options

CONFIG_PACKET=m
# CONFIG_PACKET_MMAP is not set
CONFIG_NETLINK_DEV=m
CONFIG_NETFILTER=y
CONFIG_NETFILTER_DEBUG=y
CONFIG_FILTER=y
CONFIG_UNIX=y
CONFIG_INET=y
CONFIG_IP_MULTICAST=y
CONFIG_IP_ADVANCED_ROUTER=y
CONFIG_IP_MULTIPLE_TABLES=y
CONFIG_IP_ROUTE_FWMARK=y
CONFIG_IP_ROUTE_NAT=y
CONFIG_IP_ROUTE_MULTIPATH=y
CONFIG_IP_ROUTE_TOS=y
CONFIG_IP_ROUTE_VERBOSE=y
CONFIG_IP_ROUTE_LARGE_TABLES=y
# CONFIG_IP_PNP is not set
CONFIG_NET_IPIP=m
CONFIG_NET_IPGRE=m
# CONFIG_NET_IPGRE_BROADCAST is not set
# CONFIG_IP_MROUTE is not set
# CONFIG_ARPD is not set
CONFIG_INET_ECN=y
# CONFIG_SYN_COOKIES is not set

# Ip_ Netfilter Configuration

CONFIG_IP_NF_CONNTRACK=y
CONFIG_IP_NF_FTP=m
# CONFIG_IP_NF_AMANDA is not set
# CONFIG_IP_NF_TFTP is not set
CONFIG_IP_NF_IRC=m
CONFIG_IP_NF_QUEUE=m
CONFIG_IP_NF_IPTABLES=y
CONFIG_IP_NF_MATCH_LIMIT=m
CONFIG_IP_NF_MATCH_MAC=m
CONFIG_IP_NF_MATCH_PKTTYPE=m
CONFIG_IP_NF_MATCH_MARK=m
CONFIG_IP_NF_MATCH_MULTIPORT=y
CONFIG_IP_NF_MATCH_TOS=y
CONFIG_IP_NF_MATCH_NTH=m
# CONFIG_IP_NF_MATCH_IPV4OPTIONS is not set
# CONFIG_IP_NF_MATCH_RECENT is not set
CONFIG_IP_NF_MATCH_ECN=m
CONFIG_IP_NF_MATCH_DSCP=m
CONFIG_IP_NF_MATCH_AH_ESP=m
CONFIG_IP_NF_MATCH_LENGTH=m
CONFIG_IP_NF_MATCH_TTL=m
CONFIG_IP_NF_MATCH_TCPMSS=m
CONFIG_IP_NF_MATCH_HELPER=m
CONFIG_IP_NF_MATCH_STATE=m
# CONFIG_IP_NF_MATCH_CONNLIMIT is not set
CONFIG_IP_NF_MATCH_CONNTRACK=m
# CONFIG_IP_NF_MATCH_UNCLEAN is not set
# CONFIG_IP_NF_MATCH_OWNER is not set
CONFIG_IP_NF_FILTER=m
CONFIG_IP_NF_TARGET_REJECT=m
CONFIG_IP_NF_TARGET_NETLINK=m
# CONFIG_IP_NF_TARGET_MIRROR is not set
CONFIG_IP_NF_NAT=m
CONFIG_IP_NF_NAT_NEEDED=M
CONFIG_IP_NF_TARGET_MASQUERADE=M
CONFIG_IP_NF_TARGET_REDIRECT=M
# CONFIG_IP_NF_NAT_LOCAL is not set
# CONFIG_IP_NF_NAT_SNMP_BASIC is not set
CONFIG_IP_NF_NAT_IRC=m
CONFIG_IP_NF_NAT_FTP=m
CONFIG_IP_NF_MANGLE=y
CONFIG_IP_NF_TARGET_TOS=y
CONFIG_IP_NF_TARGET_ECN=m
CONFIG_IP_NF_TARGET_DSCP=y
CONFIG_IP_NF_TARGET_MARK=y
CONFIG_IP_NF_TARGET_LOG=m
CONFIG_IP_NF_TARGET_TTL=y
CONFIG_IP_NF_TARGET_ULOG=m
CONFIG_IP_NF_TARGET_TCPMSS=m
# CONFIG_IP_NF_ARPTABLES is not set
# CONFIG_IPV6 is not set
# CONFIG_KHTTPD is not set
# CONFIG_ATM is not set
CONFIG_VLAN_8021Q=m
# CONFIG_IPX is not set
# CONFIG_ATALK is not set


^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2003-12-28  1:53 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-09-12  7:05 binding nntp to one interface Rasmus Reinholdt Nielsen
2002-09-12  9:15 ` Anders Fugmann
2002-09-12 10:22 ` Antony Stone
2002-09-12 11:31   ` IPTABLES NewBie HareRam
2002-09-12 13:54     ` Antony Stone
2002-09-14  9:23       ` NAT and NAT HareRam
     [not found] ` <5.1.0.14.2.20020912131043.02711d58@of23sm3>
2002-09-12 11:51   ` binding nntp to one interface Anders Fugmann
2002-09-12 11:55     ` Rasmus Reinholdt Nielsen
  -- strict thread matches above, loose matches on Subject: below --
2003-09-11 13:41 iptables newbie ads nat
2003-09-11 14:28 ` Pascal Vilarem
2003-12-27 13:31 Johan Cimen
2003-12-27 14:50 ` John A. Sullivan III
2003-12-27 17:05   ` Johan Cimen
2003-12-27 19:09     ` Iced Tea
2003-12-27 19:16       ` Johan Cimen
2003-12-28  1:53     ` Mark E. Donaldson
2003-12-27 21:26 ` Johan Cimen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox