From mboxrd@z Thu Jan 1 00:00:00 1970 From: Sven Schuster Subject: Re: Redirecting outgoing SMTP from LAN to another LAN server Date: Thu, 29 Apr 2004 16:47:57 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20040429144757.GA6534@zion.homelinux.com> References: <20040429095949.GB22172@acentral.co.uk> <20040429133757.GK7147@samad.com.au> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="opJtzjQTFsWo+cga" Return-path: Content-Disposition: inline In-Reply-To: <20040429133757.GK7147@samad.com.au> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org --opJtzjQTFsWo+cga Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Apr 29, 2004 at 11:37:57PM +1000, Alexander Samad told us: > On Thu, Apr 29, 2004 at 10:59:49AM +0100, Gavin Hamill wrote: > > Hullo :) > >=20 > > I'd like to do $SUBJECT, but after much playing with commands like > >=20 > > iptables -t nat -A PREROUTING -p tcp -i eth1 --dport 25 -j DNAT --to 10= =2E0.0.253:25 >=20 > what about=20 >=20 > iptables -t nat -A PREROUTING -p tcp -i eth1 -s ! 10.0.0.253 --dport 25 = -j DNAT --to 10.0.0.253:25 >=20 > I presume 10.0.0.253 is also on eth1. >=20 The problem here might be that both the client and the server are on=20 the same physical network. This means So assume we have a client (10.0.0.1) which wants to connect to a mail server (12.34.56.78) on the internet. So you DNAT the request to your internal mail server 10.0.0.253 at the firewall. Your internal mail server gets the request but will try to directly talk to the client, as in the packet the sender is still the original ip adress. (sorry if this is hard to understand, I'm not really good in=20 explaining things :) So you will additionally need a SNAT rule on your firewall, something like iptables -t nat -A POSTROUTING -p tcp -i eth1 -s 10.0.0.0/8 \ -d 10.0.0.253 --dport 25 -j SNAT --to 10.0.0.xx:25 where xx would be the ip of your firewall. Now both the packets =66rom the client to the server and the returning packets from the server to the client will travel through your firewall. HTH Sven >=20 > >=20 > > I have given up and have come to you fine people for help... > >=20 > > My LAN is on eth1, with WAN on eth0. The gateway machine is 10.0.0.254 = doing masq for=20 > > LAN clients, but I'd like to send any outgoing SMTP connections to 10.0= =2E0.253 - alas=20 > > any time I've tried, I just end up killing ALL outgoing SMTP :( > >=20 > > Any suggestions warmly received! > >=20 > > Cheers, > > Gavin. > >=20 > >=20 --=20 Linux zion 2.6.6-rc1 #1 Sat Apr 17 11:50:12 CEST 2004 i686 athlon i386 GNU/= Linux 16:37:12 up 8 days, 21:26, 1 user, load average: 0.01, 0.01, 0.00 --opJtzjQTFsWo+cga Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQFAkRWdo4FAdB2PneQRAu96AJwIjfNE3O3oJlGkWCTNo53Oo4/2JgCdGbFP Rx0lH6Rexz/nGGLJThw7n9A= =is6m -----END PGP SIGNATURE----- --opJtzjQTFsWo+cga--