From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
To: netfilter@lists.netfilter.org
Subject: Re: Routing through PtP and iptables
Date: Sat, 13 May 2006 01:56:57 +0200 [thread overview]
Message-ID: <446520C9.4040604@plouf.fr.eu.org> (raw)
In-Reply-To: <200605122335.10078.antonio.dibacco@aruba.it>
Hello,
Antonio Di Bacco a écrit :
>
> I have two identical linux boxes (A e B), each one with two interfaces: an
> ethernet (eth0 with ip 192.168.1.50) and an hdlc (hdlc0). The two boxes are
> only connected via a link through their hdlc interfaces. Because they have to
> be exactly the same, if I have to assign an ip address to hdlc0 of A then
> the hdlc0 of B should have the same ip address. Each one should have a
> default route that cannot coincide with the hdlc interface. Every linux box
> has a web server. When I connect with my notebook to box A I want to reach
> the web server on A typing in my browser http://192.168.1.50 and I want to
> reach web server on B typing http://192.168.1.50:8080 .
> Some one knows how could it be possible?
I would choose a "fake" unused address $FAKE_IP, route it through the
HDLC interface and NAT traffic on the HDLC link so that both source and
destination addresses appear to be $FAKE_IP. Of course this address must
not be assigned to any interface, else traffic to that address would be
routed locally and that's not what you want.
Same setup on both boxes (not tested) :
# IP forwarding is assumed to be enabled by any means, e.g.
sysctl -w net.ipv4.ip_forward=1
# or
echo 1 > /proc/sys/net/ipv6/ip_forward
# add route to the fake address using 'route'
route add $FAKE_IP dev 'hdlc0'
# or using 'ip'
ip route add $FAKE_IP dev hdlc0
# forwarding box setup
# 1st step : NAT destination 192.168.1.50:8080 -> $FAKE_IP:80
iptables -t nat -A PREROUTING -d 192.168.1.50 -p tcp --dport 8080 \
-j DNAT --to-destination $FAKE_IP:80
# 2nd step : NAT source on HDLC -> $FAKE_IP (for return path)
iptables -t nat -A POSTROUTING -o hdlc0 -d $FAKE_IP \
-j SNAT --to-source $FAKE_IP
# server box setup
# NAT destination on HDLC $FAKE_IP -> 192.168.1.50
iptables -t nat -A PREROUTING -i hdlc0 -d $FAKE_IP \
-j DNAT --to-destination 192.168.1.50
next prev parent reply other threads:[~2006-05-12 23:56 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-05-12 21:35 Routing through PtP and iptables Antonio Di Bacco
2006-05-12 23:56 ` Pascal Hambourg [this message]
2006-05-13 10:38 ` Rob Sterenborg
2006-05-13 12:41 ` antonio.dibacco
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=446520C9.4040604@plouf.fr.eu.org \
--to=pascal.mail@plouf.fr.eu.org \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox