Linux Netfilter discussions
 help / color / mirror / Atom feed
From: SaVaGE <pc-secure@home.nl>
To: netfilter@lists.samba.org
Subject: Re: Problems removing rules
Date: Thu, 1 May 2003 05:02:48 +0200	[thread overview]
Message-ID: <200305010502.48739.pc-secure@home.nl> (raw)
In-Reply-To: <20030501000717.46647.qmail@web14308.mail.yahoo.com>

Op donderdag 1 mei 2003 02:07, schreef Intercomax:
> I'm having a huge problem:
>
> I have those rules:
>
> Chain PREROUTING (policy ACCEPT)
> target     prot opt source               destination
> DNAT       tcp  --  anywhere             anywhere
>      tcp dpt:www
> to:192.168.0.1:80
>
> Chain POSTROUTING (policy ACCEPT)
> target     prot opt source               destination
> MASQUERADE  all  --  anywhere             anywhere
>
> Chain OUTPUT (policy ACCEPT)
> target     prot opt source               destination
>
> I inserted iptables -t nat -I PREROUTING -s
> xxx.xxx.xxx.xxx -j RETURN
>
> OK. The rules works fine.
>
> Then I removed the RETURN iptables -t nat -D
> PREROUTING -s
> xxx.xxx.xxx.xxx -j
> RETURN and... The IP still access some pages that
> accessed before!
>
> Why?
>
> I need to redirect all internal requests to a specific
> page and then,
> after a
> login, masquerade them to the Internet...
>
> That's it.
>
> Thanks in advance.
>
> Maurício S. Mudrik
>
> _______________________________________________________________________
> Yahoo! Mail
> O melhor e-mail gratuito da internet: 6MB de espaço, antivírus, acesso
> POP3, filtro contra spam. http://br.mail.yahoo.com/

As far I can see by your rules , your running a Web-server on 192.168.0.1:80  
, not specific a rule to aply local acces to the internet.

But as i see the POSTROUTING chain , i miss something namely your output 
interface !!  like this ::;
Chain POSTROUTING (policy DROP)
num  pkts bytes target        prot       opt      in   out     source      
  *        *     * MASQUERADE  all  --  *         *    eth0    0.0.0.0/0            

destination
0.0.0.0/0

what about that login , i think Squid could do something like that , so you 
have to use a proxy for that.

Pascal


  reply	other threads:[~2003-05-01  3:02 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-05-01  0:07 Problems removing rules Intercomax
2003-05-01  3:02 ` SaVaGE [this message]
  -- strict thread matches above, loose matches on Subject: below --
2003-04-26 17:35 Local rule for Port Forward Andy Wood
2003-04-30 21:04 ` Patrick Nelson
2003-04-30 17:58   ` Problems removing rules Maurício S. Mudrik

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200305010502.48739.pc-secure@home.nl \
    --to=pc-secure@home.nl \
    --cc=netfilter@lists.samba.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox