From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: Send local traffic to a different server.
Date: Wed, 23 Jun 2004 15:00:05 +0100 [thread overview]
Message-ID: <200406231500.05742.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <1088001203.4009.45.camel@simpsonb.hillsboroughcounty.org>
On Wednesday 23 June 2004 3:33 pm, Brett Simpson wrote:
> On Wed, 2004-06-23 at 09:33, Antony Stone wrote:
> > On Wednesday 23 June 2004 3:08 pm, Brett Simpson wrote:
> > > I've tried a number of different PREROUTING and POSTROUTING rules and
> > > can't seem to make this work.
> > >
> > > I have a system with a single nic (eth0). While I'm on the system via a
> > > shell I would like to connect to 127.0.0.1:6000 and get seemlessly
> > > translated to 207.156.7.15:80.
> > >
> > > I tried the following without success:
> > >
> > > iptables -t nat -A PREROUTING -p tcp -d 127.0.0.1 -i lo --dport 6000
> > > -j DNAT--to-destination 207.156.7.15:80
> > >
> > > iptables -t nat -A POSTROUTING -p tcp -d 207.156.7.15 -o eth0 --dport
> > > 80 -j SNAT --to-source 127.0.0.1
> >
> > Try:
> >
> > iptables -A OUTPUT -t nat -p tcp --dport 6000 -d 127.0.0.1 -j DNAT --to
> > 207.156.7.15:80
>
> Didn't work. Would the INPUT chain help?
No, I don't think so. INPUT is only for the reply packets. I'm assuming
you're allowing those back in to your machine (!?), so the problem is getting
the outbound packets to the right destination with the right return address.
> iptables -t nat -A OUTPUT -p tcp --dport 6000 -d 127.0.0.1 -j DNAT --to
> 207.156.7.15:80
> iptables -t nat -A POSTROUTING -p tcp -d 207.156.7.15 -o eth0 --dport 80
> -j SNAT --to-source 127.0.0.1
Duh :) I forgot about the reply address :)
My rule will send packets to 207.156.7.15 with a source address of 127.0.0.1
Not surprisingly, you don't get anything back...
Try:
iptables -A OUTPUT -t nat -p tcp --dport 6000 -d 127.0.0.1 -j DNAT --to
207.156.7.15:80
iptables -A POSTROUTING -t nat -p tcp --dport 80 -d 207.156.7.15 -s 127.0.0.1
-j SNAT --to a.b.c.d
Where a.b.c.d is the routable address of your machine, to which reply packets
can successfully return.
Regards,
Antony.
--
Behind the counter a boy with a shaven head stared vacantly into space,
a dozen spikes of microsoft protruding from the socket behind his ear.
- William Gibson, Neuromancer (1984)
next prev parent reply other threads:[~2004-06-23 14:00 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-06-23 14:08 Send local traffic to a different server Brett Simpson
2004-06-23 13:33 ` Antony Stone
2004-06-23 14:33 ` Brett Simpson
2004-06-23 14:00 ` Antony Stone [this message]
2004-06-23 15:12 ` Brett Simpson
2004-06-23 14:24 ` Antony Stone
2004-06-23 16:41 ` Brett Simpson
2004-06-24 18:27 ` Brett Simpson
2004-06-23 14:20 ` John A. Sullivan III
2004-06-23 14:58 ` Antony Stone
2004-06-23 16:34 ` Brett Simpson
2004-06-23 15:39 ` B. McAninch
2004-06-23 16:53 ` Brett Simpson
-- strict thread matches above, loose matches on Subject: below --
2004-06-23 15:26 Aldo Lagana
2004-06-24 8:46 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200406231500.05742.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox