Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Rimas" <rmocius@auste.elnet.lt>
To: netfilter@lists.netfilter.org
Subject: Re: Port Forwarding
Date: Wed, 3 Dec 2003 16:38:20 -0000	[thread overview]
Message-ID: <05ed01c3b9bb$dcc24d10$6e69690a@RIMAS> (raw)
In-Reply-To: 200312031627.hB3GRhNC028551@server5.bandwidthco.com

Thanks guys for the help. It help me.

I have another iptables setmark question.
This is a small part of my script:

The line below is OK
iptables -t mangle -A PREROUTING -i eth2 -s 10.105.105.0/24 -p tcp --dport
1723 -j MARK --set-mark 0x960

But how mark just IP port 47, because the line below does not I want.
iptables -t mangle -A PREROUTING -i eth2 -s 10.105.105.0/24 -p 47 -j
MARK --set-mark 0x960

ip rule add fwmark 0x960 table localvpn
ip route add default via $P2 dev eth0 table localvpn



Thanks in advance

Remus



----- Original Message ----- 
From: "Mark E. Donaldson" <markee@bandwidthco.com>
To: "'Remus'" <rmocius@auste.elnet.lt>; <netfilter@lists.netfilter.org>
Sent: Wednesday, December 03, 2003 4:27 PM
Subject: RE: Port Forwarding


> A method that works well for me, and I use it extensively, is to place all
> your IP addresses in a text file, and feed the file to the script.  With
> this method, all you need to do is update (edit) the text file as needed
for
> adding or deleting IP's.  For instance, if you wanted to sneak TFTP
through
> the firewall (which I don't really recommend), you could add this rule:
>
> ####################################################################
> # TFTP
> ####################################################################
> # if TFTP enabled redirect to port 69 on internal TFTP server
> if [ "$TFTP_SERVER" = "1" ] ;
> then
> while read TRUSTED;
> do
> $IPT -t nat -A PREROUTING -p udp -s $TRUSTED
> --destination-port 69 -i $FW_INET_IFACE -j LOG --log-level $LOG_LEVEL
> --log-prefix "DNAT IN TFTP OK: "
> $IPT -t nat -A PREROUTING -p udp -s $TRUSTED
> --destination-port 69 -i $FW_INET_IFACE -j DNAT --to-destination
> $INTERNAL_TFTP:69
> done < $TRUSTED_LIST
> fi
>
> -----Original Message-----
> From: netfilter-admin@lists.netfilter.org
> [mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Remus
> Sent: Wednesday, December 03, 2003 12:27 AM
> To: netfilter@lists.netfilter.org
> Subject: Port Forwarding
>
> Hi folks,
>
> I have a PREROUTING rule:
> iptables -t nat -A PREROUTING -d $EXTERNALIP_1 -s some_external_IP -p
47 -j
> DNAT --to 192.168.0.19
>
> How to add more source addresses which will be able to connect?
>
>
> Thanks in advance
>
> Remus
>
>
>



  reply	other threads:[~2003-12-03 16:38 UTC|newest]

Thread overview: 65+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-12-04  5:43 Forwarding and masquerading got broken Lawrence G. Hunsicker
2003-12-03  8:26 ` Port Forwarding Remus
2003-12-03  8:44   ` Rob Sterenborg
2003-12-03  8:44   ` Ray Leach
2003-12-03 16:27   ` Mark E. Donaldson
2003-12-03 16:38     ` Rimas [this message]
  -- strict thread matches above, loose matches on Subject: below --
2009-10-11 13:56 jen140
2009-10-11  2:00 jen140
2009-10-11  0:30 jen140
2009-10-11  1:36 ` John A. Sullivan III
2009-10-11  8:16 ` Brian Austin - Standard Universal
2009-10-11  8:37 ` Pascal Hambourg
2009-05-28 19:50 Barry A Rich
2009-06-05 13:47 ` Aleksander Kamenik
2008-12-12 23:33 Port forwarding Błażej Ślusarek
2008-12-13 16:36 ` Elvir Kuric
2009-02-04 17:48 ` Błażej Ślusarek
2009-02-04 18:38   ` Ivan Petrushev
2006-02-28 13:27 Stian B. Barmen
2005-02-23  8:36 port forwarding DurgaPrasad Adusumalli
2004-11-16 17:01 port Forwarding diadicic
2004-11-16 16:44 diadicic
2004-11-16 16:48 ` Jason Opperisano
2004-10-28  4:30 Port forwarding Mike
2004-10-28 12:50 ` Jason Opperisano
     [not found] <20040917135140.AE3C66A5@mail.817west.com>
2004-09-17 13:57 ` Jason Opperisano
2004-09-17 14:09   ` KUCKAERTZ Régis - NVISION
     [not found]   ` <-4718906956710508172@unknownmsgid>
2004-09-19 10:06     ` Mohamed Eldesoky
     [not found] <20040917132253.B6B1E6A5@mail.817west.com>
2004-09-17 13:33 ` Jason Opperisano
2004-09-17 13:52   ` KUCKAERTZ Régis - NVISION
     [not found] <20040917123138.EC8FE6A5@mail.817west.com>
2004-09-17 12:55 ` Jason Opperisano
2004-09-17 13:23   ` KUCKAERTZ Régis - NVISION
2004-09-17 12:32 KUCKAERTZ Régis - NVISION
2004-06-28  9:16 Gunnar Frödin
2004-06-28  9:57 ` Antony Stone
2004-06-28 10:18   ` Gunnar Frödin
2004-06-28 10:34     ` Antony Stone
2004-06-28 12:20       ` Gunnar Frödin
2004-06-28 12:52         ` Antony Stone
2004-06-28 13:21           ` Gunnar Frödin
2003-12-03 16:27 Port Forwarding Mark E. Donaldson
2003-10-29  2:24 Fritz Mesedilla
2003-10-28 13:12 Babar Kazmi
2003-10-28 12:49 Gaby Schilders
2003-10-27 22:17 Jason Mallory
2003-10-28 10:54 ` Rob Sterenborg
2003-09-26  8:37 Aris  Santillan
2003-07-23  6:41 port forwarding George Vieira
2003-07-23  6:06 Sathi
2003-07-23  8:02 ` Nils Juergens
2003-06-05 23:08 Port forwarding George Vieira
2003-06-04 19:53 Question about nfmark Cedric Blancher
2003-06-05  9:48 ` Port forwarding Dhyanesh Ramaiya
2003-06-06  8:15   ` Philip Craig
2003-06-06 10:23     ` Dhyanesh Ramaiya
2003-04-27  9:09 port forwarding Fox
2003-04-27  9:37 ` Rob Sterenborg
2003-04-24  5:58 Port Forwarding Brei, Matt
2003-04-24 17:26 ` Dan Egli
2003-04-24  5:20 Port forwarding Brei, Matt
2002-12-05 20:56 port forwarding Maxim Berlin
2002-12-07  7:16 ` Andrew Smith
2002-12-07 12:11   ` Roy Sigurd Karlsbakk
2002-12-07 13:03     ` Andrew Smith
2002-12-07 13:45       ` Roy Sigurd Karlsbakk
2002-12-07 14:14         ` Andrew Smith

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='05ed01c3b9bb$dcc24d10$6e69690a@RIMAS' \
    --to=rmocius@auste.elnet.lt \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox