Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Robby Workman <robby@rlworkman.net>
To: Scott Mayo <scotgmayo@gmail.com>
Cc: netfilter@vger.kernel.org
Subject: Re: Public IP to Private IP
Date: Mon, 27 Jan 2014 13:36:24 -0600	[thread overview]
Message-ID: <20140127133624.7d917b1e.robby@rlworkman.net> (raw)
In-Reply-To: <CAFPGR9jhpurA644xdfWc6dF58iVCc5t7mbUw6NsjxPqYQxtUHw@mail.gmail.com>

On Mon, 27 Jan 2014 13:22:17 -0600
Scott Mayo <scotgmayo@gmail.com> wrote:

> I am having some troubles getting my public IPs routed to my private
> IPs.
> 
> Here is an example.
> Private IP of the main server with my IPTables:  192.168.0.1
> Public IP of the main server:  1.1.1.1
> I also have 1.1.1.2 and 1.1.1.3 as public IPs attached to the public
> nic. Domain name example.org is pointed to 1.1.1.2
> 
> I am trying to get the following public IPs to Private IPs:
> 1.1.1.2 -> 192.168.0.2
> 1.1.1.3 -> 192.168.0.3
> 
> If I am outside my network and go to example.org, it seems to work
> fine. If I am inside my network and go to 192.168.0.2 then it works
> fine. If I go to example.org from inside my network then it goes back
> to 192.168.0.1 instead of 192.168.0.2
> 
> Maybe this does not have to do with IPTables even since it works with
> an IP, but I thought I would ask here.  I do not have an internal DNS
> server.
> 
> Here are the rules that I have:
> 
> IPTABLES -t nat -A PREROUTING -d 1.1.1.2 -p tcp -j DNAT
> --to-destination 192.168.0.2
> IPTABLES -t nat -A POSTROUTING -d 192.168.0.2 -j SNAT
> --to-destination 1.1.1.2
> 
> Any suggestions would be appreciated.


The best solution (IMHO) is to handle it internally with DNS, i.e.
have the names you expect to see on those public ip addresses resolve
to the internal addresses from inside the local network.

-RW

  reply	other threads:[~2014-01-27 19:36 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-01-27 19:22 Public IP to Private IP Scott Mayo
2014-01-27 19:36 ` Robby Workman [this message]
2014-01-27 20:08 ` Mike Wright
2014-01-27 20:46 ` Bob Reiber
2014-01-27 20:48 ` Ray Soucy
2014-01-27 21:01   ` Scott Mayo
2014-01-27 21:30     ` Ray Soucy
2014-02-02 15:45     ` Pascal Hambourg
2014-02-02 16:09       ` Mauricio Tavares
2014-02-02 16:36         ` Pascal Hambourg
2014-01-28  7:32 ` Rob Sterenborg (lists)
2014-02-24 18:22 ` Scott Mayo
2014-02-24 19:13   ` Scott Mayo
2014-02-24 21:56     ` Scott Mayo
2014-02-25 18:06       ` Scott Mayo
2014-02-25 18:12         ` Scott Mayo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20140127133624.7d917b1e.robby@rlworkman.net \
    --to=robby@rlworkman.net \
    --cc=netfilter@vger.kernel.org \
    --cc=scotgmayo@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox