Linux Netfilter discussions
 help / color / mirror / Atom feed
* OK dumb questions
@ 2003-12-11 18:09 Michael Gale
  2003-12-11 18:51 ` Antony Stone
  0 siblings, 1 reply; 5+ messages in thread
From: Michael Gale @ 2003-12-11 18:09 UTC (permalink / raw)
  To: netfilter

Hello,

	I have a firewall setup with the default policy to block.

I have a DNAT rule to DNAT incoming connections to a internal IP.
I then have a EXT to INT forward rule for port 80 - state NEW
I then have a EXT to INT forward rule for ESTABLISHED connections
I then have a INT to EXT forward rule for ESTABLISHED connections

This is working great the problem ...

I am not able to get this machine to make a out bound connection :(

I tried enabling logging and nothing ... it is NOT until I change the default policy to ACCEPT that I can make a out bound connection.

The only difference in the log files is that with the default set to ACCEPT it makes it to the NATPOST target ...

The NAT tables have a default of ACCEPT from the beginning


-- 
Michael Gale
Network Administrator
Utilitran Corporation


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-12-11 19:33 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-11 18:09 OK dumb questions Michael Gale
2003-12-11 18:51 ` Antony Stone
2003-12-11 19:16   ` Michael Gale
2003-12-11 19:24     ` Antony Stone
2003-12-11 19:33     ` Jeffrey Laramie

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox