From: Alistair Tonner <Alistair@nerdnet.ca>
To: Reuven Kohanim <rkohanim@yahoo.com>, netfilter@lists.netfilter.org
Subject: Re: seeking help on iptable/netfilter and X protocol
Date: Mon, 12 May 2003 11:59:13 -0400 [thread overview]
Message-ID: <200305121159.13974.Alistair@nerdnet.ca> (raw)
In-Reply-To: <20030512131114.86082.qmail@web41704.mail.yahoo.com>
On May 12, 2003 09:11 am, Reuven Kohanim wrote:
> I have been successfully using X protocol across an
> ipchains gateway. I am trying to move to iptables.
> Finally ,and thanks to some help that I got at this
> forum, everything is working smoothly except for X.
>
> I am bypassing masquerading when my source/destination
> are the X client/server so that I can use my
> non-masqed ip address for the 'display' parameter of
> say xterm application. Could anyone tell me if
> iptables
> does or does not supports X.
>
> Thanks
> Reuven
>
>
> __________________________________
> Do you Yahoo!?
> The New Yahoo! Search - Faster. Easier. Bingo.
> http://search.yahoo.com
I've found with the simple expedient of setting appropriate rules for
source IP and dest ip I can manage my X connections through Iptables.
I prefer to have outside X connections initiated from within ssh ... it is
more secure, and easier to manage on a per user basis, (I dont have to add a
new rule for each connection site.) since ssh handles X forwarding for the
client.
What masquerading are you bypassing and why? --
if you are connecting to a remote site and exporting to a non routeable IP
your X connection will not work ... if you are connecting internally and
using your local ip, that should work ... but even then, if the ip is non
routeable (or private as some call them) you might have problems.
--
Alistair Tonner
nerdnet.ca
Senior Systems Analyst - RSS
Any sufficiently advanced technology will have the appearance of magic.
Lets get magical!
prev parent reply other threads:[~2003-05-12 15:59 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-05-12 13:11 seeking help on iptable/netfilter and X protocol Reuven Kohanim
2003-05-12 15:59 ` Alistair Tonner [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200305121159.13974.Alistair@nerdnet.ca \
--to=alistair@nerdnet.ca \
--cc=netfilter@lists.netfilter.org \
--cc=rkohanim@yahoo.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox