From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: DMZ to DMT through ROUTER problem !
Date: Thu, 20 May 2004 16:07:10 +0100 [thread overview]
Message-ID: <200405201607.10019.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <200405201658.59945.liste@zerozone.it>
On Thursday 20 May 2004 3:58 pm, O-Zone wrote:
> On Thursday 20 May 2004 16:45, Antony Stone wrote:
> > Yes, but that destination address has already been changed by your
> > PREROUTING rule, and is now 192.168.0.0/24 - that's the whole point. If
> > the destination address had not been changed (ie: if the client had
> > contacted the server's real IP address instead of a pretend one), you
> > wouldn't need to change the source address as well.
>
> As you say, the problem was when a server with 192.168.0.x, passing through
> 192.168.0.1 (that is the ROUTER), and try to connect to 151.8.47.x (the
> real server's PUBLIC IP). This is the desidered flow:
>
> 192.168.0.2-->151.8.47.A-->192.168.0.3
>
> So i think that i need additiona rules to MASQ/DNAT connection to
> 151.8.47.x !
Well, yes, but this PREROUTING DNAT rule is needed for connections from the
outside, which you say are working fine already?
I quote from your original posting:
- Hi all,
- i've a big problem. Here's a little diagram:
-
- [INTRANET 10.0.0.0/24]-------------+
- +--[ROUTER]--(NET)
- [DMZ SERVER A - 192.168.0.2]----+
- [DMZ SERVER B - 192.168.0.3]----+
-
- Each DMZ server is mapped to it's PUBLIC IP. For example:
-
- 151.8.47.A ----> 192.168.0.2
- 151.8.47.B ----> 192.168.0.3
-
- and all work perfectly !!!"
If you do not in fact already have the PREROUTING DNAT rules, then what do you
mean by "Each DMZ server is mapped to its PUBLIC IP"? Maybe I misunderstood
what you have already done, and already have working, and what problem is
still left to solve?
Regards,
Antony.
--
"Reports that say that something hasn't happened are always interesting to me,
because as we know, there are known knowns; there are things we know we know.
We also know there are known unknowns; that is to say we know there are some
things we do not know. But there are also unknown unknowns - the ones we
don't know we don't know."
- Donald Rumsfeld, US Secretary of Defence
Please reply to the list;
please don't CC me.
next prev parent reply other threads:[~2004-05-20 15:07 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-05-20 11:18 DMZ to DMT through ROUTER problem ! O-Zone
2004-05-20 12:30 ` Antony Stone
2004-05-20 12:54 ` O-Zone
2004-05-20 13:22 ` Antony Stone
2004-05-20 14:37 ` O-Zone
2004-05-20 14:45 ` Antony Stone
2004-05-20 14:58 ` O-Zone
2004-05-20 15:07 ` Antony Stone [this message]
2004-05-20 15:53 ` O-Zone
2004-05-20 16:07 ` Antony Stone
2004-05-20 16:32 ` O-Zone
2004-05-20 17:34 ` Antony Stone
2004-05-20 17:44 ` Antony Stone
2004-05-21 9:30 ` O-Zone
2004-05-21 10:19 ` Antony Stone
2004-05-21 14:08 ` O-Zone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200405201607.10019.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox