From mboxrd@z Thu Jan 1 00:00:00 1970 From: Henry Ritzlmayr Subject: RE: Masquerading on local ports Date: 20 Mar 2003 17:26:49 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1048177609.1493.127.camel@localhost.localdomain> References: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Netfilter Mailing List Am Don, 2003-03-20 um 16.29 schrieb Rob Sterenborg: > > And here is the question. How is it possible to nat a lokal port? > > > > IPTABLES -t nat -A PREROUTING -p tcp -d 127.0.0.1 > > --destination-port 81 -j DNAT --to-destination 127.0.0.1:80 > > > > telnet localhost 80 <<< works > > telnet localhost 81 <<< Connection refused > > iptables -t nat -A PREROUTING -d 127.0.0.1 -p tcp --dport 80 -j REDIRECT > --to-ports 81 > > > Rob Tanks for the answer, I tried that one already but it behaves the same. I also tried IPTABLES -t nat -A PREROUTING -p tcp -d 172.16.172.12 --destination-port 81 -j REDIRECT --to-ports 80 wich works perfect for both port 80 and 81 from a foreign host. Henry