Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Alistair Tonner <Alistair@nerdnet.ca>
To: Reuven Kohanim <rkohanim@yahoo.com>, netfilter@lists.netfilter.org
Subject: Re: seeking help on iptable/netfilter and X protocol
Date: Mon, 12 May 2003 11:59:13 -0400	[thread overview]
Message-ID: <200305121159.13974.Alistair@nerdnet.ca> (raw)
In-Reply-To: <20030512131114.86082.qmail@web41704.mail.yahoo.com>

On May 12, 2003 09:11 am, Reuven Kohanim wrote:
> I have been successfully using X protocol across an
> ipchains gateway. I am trying to move to iptables.
> Finally ,and thanks to some help that I got at this
> forum, everything is working smoothly except for X.
>
> I am bypassing masquerading when my source/destination
> are the X client/server so that I can use my
> non-masqed ip address for the 'display' parameter of
> say xterm application. Could anyone tell me if
> iptables
> does or does not supports X.
>
> Thanks
> Reuven
>
>
> __________________________________
> Do you Yahoo!?
> The New Yahoo! Search - Faster. Easier. Bingo.
> http://search.yahoo.com

	I've found with the simple expedient of setting appropriate rules for 
	source IP and dest ip I can manage my X connections through Iptables.
	I prefer to have outside X connections initiated from within ssh ... it is
	more secure, and easier to manage on a per user basis, (I dont have to add a
	new rule for each connection site.) since ssh handles X forwarding for the
	client.

	What masquerading are you bypassing and why?  -- 
	if you are connecting to a remote site and exporting to a non routeable IP 
	your X connection will not work ... if you are connecting internally and
	using your local ip, that should work ... but even then, if the ip is non
	routeable (or private as some call them) you might have problems.

-- 

	Alistair Tonner
	nerdnet.ca
	Senior Systems Analyst - RSS
	
     Any sufficiently advanced technology will have the appearance of magic.
	Lets get magical!


      reply	other threads:[~2003-05-12 15:59 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-05-12 13:11 seeking help on iptable/netfilter and X protocol Reuven Kohanim
2003-05-12 15:59 ` Alistair Tonner [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200305121159.13974.Alistair@nerdnet.ca \
    --to=alistair@nerdnet.ca \
    --cc=netfilter@lists.netfilter.org \
    --cc=rkohanim@yahoo.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox