Linux Netfilter discussions
 help / color / mirror / Atom feed
* VLANs and DNAT
@ 2003-07-24 23:40 Damien Mason
  2003-07-25 10:17 ` Chris Wilson
  0 siblings, 1 reply; 6+ messages in thread
From: Damien Mason @ 2003-07-24 23:40 UTC (permalink / raw)
  To: netfilter

Hi Everyone,

    I have two interfaces, eth1 and eth2

    I have multiple vlans on a eth1, that is, eth1.1 and eth1.2, eth1.3

    Eth2 is the external interface to the internet.

    Vlan1 uses the following network address:    192.168.50.0/24
    Vlan2 uses the following network address:    192.168.50.0/24 also

    Vlan3 uses the following network address: 192.168.10.0/24

I have NAT working for the vlans, that is, clients are able to access 
the external internet using nat.

    However, there are servers on Vlan2 which I would like to forward 
traffic to from the external interface, I would imagine that I could do 
something like:

iptables -A PREROUTING -t nat -p tcp -d 203.221.181.27 --dport 80 -j 
DNAT --to 192.168.50.10:80

But I cannot specify an interface -i eth1.2 in the prerouting, because 
it occurs pre-routing?

    How can I forward traffic to a host on a vlan when the vlans don't 
use unique addressing schemes?.. I was thinking I may have to -j 
REDIRECT the traffic to another chain, and forward it from there?

    Any Ideas or solutions would be most appreciated :)

Thanks in advance,
    Damien Mason



-- 


Best Regards,

Damien Mason
SuSE Systems Specialist

SuSE Linux Asia-Pacific
2-6 Waltham Street
Artarmon, NSW 2064, Australia

Telephone: (612) 943 943 94 ext 246
Facsimile: (612) 9437 3839
Email: kinetic@suse.net.au 
<mailto:kinetic@suse.net.au?subject=Reply%20Email>
Web: http://www.suse.net.au./



^ permalink raw reply	[flat|nested] 6+ messages in thread
* VLANs and DNAT
@ 2003-07-24  6:53 Damien Mason
  0 siblings, 0 replies; 6+ messages in thread
From: Damien Mason @ 2003-07-24  6:53 UTC (permalink / raw)
  To: netfilter

Hi Everyone,

	I have two interfaces, eth1 and eth2

	I have multiple vlans on a eth1, that is, eth1.1 and eth1.2,
eth1.3

	Eth2 is the external interface to the internet.

	Vlan1 uses the following network address:	192.168.50.0/24
	Vlan2 uses the following network address:	192.168.50.0/24
also

	Vlan3 uses the following network address: 192.168.10.0/24

I have NAT working for the vlans, that is, clients are able to access
the external internet using nat.

	However, there are servers on Vlan2 which I would like to
forward traffic to from the external interface, I would imagine that I
could do something like:

iptables -A PREROUTING -t nat -p tcp -d 203.221.181.27 --dport 80 -j
DNAT --to 192.168.50.10:80

But I cannot specify an interface -i eth1.2 in the prerouting, because
it occurs pre-routing?

	How can I forward traffic to a host on a vlan when the vlans
don't use unique addressing schemes?.. I was thinking I may have to -j
REDIRECT the traffic to another chain, and forward it from there?

	Any Ideas or solutions would be most appreciated :)

Regards,
	Damien Mason







^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-07-26 16:07 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-07-24 23:40 VLANs and DNAT Damien Mason
2003-07-25 10:17 ` Chris Wilson
2003-07-25 13:40   ` Ramin Dousti
2003-07-25 13:54     ` Chris Wilson
2003-07-26 16:07       ` Damien Mason
  -- strict thread matches above, loose matches on Subject: below --
2003-07-24  6:53 Damien Mason

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox