From: Jason Opperisano <opie@817west.com>
To: netfilter@lists.netfilter.org
Subject: Re: Transparent gateway
Date: Thu, 18 Nov 2004 08:41:51 -0500 [thread overview]
Message-ID: <1100785310.3848.20.camel@hubcap.ljm.dom> (raw)
In-Reply-To: <419C7FE2.8060002@mattiamartinello.com>
On Thu, 2004-11-18 at 05:56, Mattia Martinello wrote:
> Hi,
>
> I'm using a netfilter gateway between my LAN and the server on the DMZ.
> This gateway makes a DNAT from 192.168.1.* to the external IP of the
> server on the DMZ.
why?
> Then, if I call http://[my external IP], the gateway makes a DNAT to
> http://192.168.20.x (the internal DMZ IP of the server), through the
> 192.168.20.254 interface.
because you told it to...
> The problem is that when I call Apache on the server, Apache thinks that
> I am 192.168.20.254, not 192.168.1.x.
> So, in the access logs the connection is made from the DMZ interface of
> the gateway and not from the real IP address of the client.
> This make me some real problems about client autentication.
>
> How I can I get my gateway transparent and solve this problem to let
> Apache to write the correct IP address of the client in the logs?
don't NAT traffic from your LAN to your DMZ. if clients inside the LAN
are requesting the public IP of the DMZ server and not it's actual DMZ
IP, you'll need something along the lines of:
iptables -t nat -A PREROUTING -i ${INSIDE_IF} -s ${INSIDE_NET} \
-d ${WEBSRV_PUB_IP} -j DNAT --to-destination ${WEB_SRV_DMZ_IP}
and make sure your outbound SNAT/MASQ for the internal net specifies the
external interface:
iptables -t nat -A POSTROUTING -o ${OUTSIDE_IF} -s ${INSIDE_NET} \
-j SNAT --to-source ${OUTSIDE_IP}
other than that--you haven't provided near enough information to answer
your questions (hint: post your rules [1])
-j
[1] iptables -t mangle -vnxL && iptables -t nat -vnxL && iptables -vnxL
--
"You must be the man who didn't know whether it was a blister or
a boil.
It was a gummi bear."
--The Simpsons
next prev parent reply other threads:[~2004-11-18 13:41 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-11-18 10:56 Transparent gateway Mattia Martinello
2004-11-18 13:41 ` Jason Opperisano [this message]
2004-11-18 13:56 ` Mattia Martinello
2004-11-18 14:17 ` Jason Opperisano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1100785310.3848.20.camel@hubcap.ljm.dom \
--to=opie@817west.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox