From mboxrd@z Thu Jan 1 00:00:00 1970 From: SaVaGE Subject: Re: Re[2]: PREROUTING Date: Tue, 29 Apr 2003 15:33:53 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <200304291533.53756.pc-secure@home.nl> References: <13955288009.20030429092330@o2.pl> <200304290949.10989.pc-secure@home.nl> <50633741.20030429145355@o2.pl> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <50633741.20030429145355@o2.pl> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Op dinsdag 29 april 2003 14:53, schreef netfilter_user: > Hello SaVaGE, > > Tuesday, April 29, 2003, 9:49:10 AM, you wrote: > > S> Op dinsdag 29 april 2003 09:23, schreef netfilter_user: > >> Hello everyone, > >> > >> this is my problem: > >> My LAN is connected to Internet via Linux machine with 2 interface ( > >> ppp0 - for internet and eth1 for local net). I need to connect from > >> local host, service that is running on port 23073 and 23083 UDP in > >> internet. For this i wrote afew rules with PREROUTING but when I sta= rt > >> script with rules below i receive: > >> > >> Bad argument `PREROUTING' > >> Try `iptables -h' or 'iptables --help' for more information. > >> Bad argument `PREROUTING' > >> Try `iptables -h' or 'iptables --help' for more information. > >> > >> > >> iptables -t nat -A PREROUTING -p udp -d 80.50.60.185 --dport 23073 -= j > >> DNAT --to-destination 192.168.1.2 iptables -t nat -A PREROUTING -p u= dp > >> -d 80.50.60.185 --dport 23083 -j DNAT --to-destination 192.168.1.2 > >> > >> iptables -A FORWARD -p udp -d 192.168.1.2 --dport 23073 -j ACCEPT > >> iptables -A FORWARD -p udp -d 192.168.1.2 --dport 23083 -j ACCEPT > >> > >> What maybe a reason of this msg? > >> Im using slackware 8.1 with iptables 1.2.6a > > S> This behaviour is correct NATting is done on the POSTROUTING table != !!! > > > S> Pascal (PC-Secure Dutch security service) > > ammm....im afraid its not correct because I have received msg like this= : > > Bad argument `PREROUTING' > Try `iptables -h' or 'iptables --help' for more information. > Bad argument `PREROUTING' > Try `iptables -h' or 'iptables --help' for more information. > > ...its not correct in my newbe opinion. Sorry my fault wasn't wake at that time , maybe this will help:: iptables -A PREROUTING -t nat -p udp -d 80.50.60.185 --dport 23073 -j DNAT --to 192.168.1.2:23073 iptables -A PREROUTING -t nat -p udp -d 80.50.60.185 --dport 23083 -j DNAT --to 192.168.1.2:23083 let us know if it worked for you !