From: Balazs Fulop <balazs.fulop@initon.com>
To: netfilter@lists.netfilter.org
Subject: DNAT not working
Date: Fri, 22 Dec 2006 16:03:30 +0100 [thread overview]
Message-ID: <458BF3C2.4050700@initon.com> (raw)
Dear List!
I have the following setup:
eth0 (WAN, with multiple alias IPs), eth1 (LAN1), eth2 (LAN2), eth3 (LAN3)
I would like to setup DNAT, in order to achieve the following:
packets coming from eth0 to a certain IP and tcp port get NATed to an IP
and port for a machine on one of the LAN subnets
I have read the relevant HOWTO and made the following setup:
# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use
Iface
aaa.bbb.ccc.ddd 0.0.0.0 255.255.255.248 U 0 0
0 eth0
192.168.5.0 0.0.0.0 255.255.255.0 U 0 0 0 eth3
192.168.4.0 0.0.0.0 255.255.255.0 U 0 0 0 eth2
192.168.3.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
0.0.0.0 aaa.bbb.ccc.eee 0.0.0.0 UG 0 0
0 eth0
# cat /var/lib/iptables/testing
# Generated by iptables-save v1.3.5 on Fri Dec 22 14:23:36 2006
*mangle
:PREROUTING ACCEPT [1804:164934]
:INPUT ACCEPT [1576:145710]
:FORWARD ACCEPT [208:12864]
:OUTPUT ACCEPT [988:111965]
:POSTROUTING ACCEPT [1239:130436]
COMMIT
# Completed on Fri Dec 22 14:23:36 2006
# Generated by iptables-save v1.3.5 on Fri Dec 22 14:23:36 2006
*nat
:PREROUTING ACCEPT [58:10171]
:POSTROUTING ACCEPT [13:1459]
:OUTPUT ACCEPT [13:1459]
-A PREROUTING -d aaa.bbb.ccc.fff -i eth0 -p tcp -m tcp --dport 25 -j
DNAT --to-destination 192.168.3.1
-A PREROUTING -j LOG --log-prefix "PREROUTING: " --log-level 7
COMMIT
# Completed on Fri Dec 22 14:23:36 2006
# Generated by iptables-save v1.3.5 on Fri Dec 22 14:23:36 2006
*filter
:INPUT ACCEPT [1576:145710]
:FORWARD ACCEPT [208:12864]
:OUTPUT ACCEPT [988:111965]
-A FORWARD -d 192.168.3.1 -i eth0 -o eth1 -p tcp -m tcp --dport 25 -j
ACCEPT
-A FORWARD -j LOG --log-prefix "FORWARD: " --log-level 7
COMMIT
# Completed on Fri Dec 22 14:23:36 2006
If I telnet 192.168.3.1 25 on the firewall, an SMTP session starts. If I
telnet from outside (coming on eth0), it waits until timeout. I just
can't figure out why it is not working. At last I removed all the IP
aliases, and it didn't work that way either. There is nothing relevant
in /var/log/syslog. I have 1 in /proc/sys/net/ipv4/ip_forward.
Please help. Thanks in advance.
Yours sincerely,
Fülöp Balázs
next reply other threads:[~2006-12-22 15:03 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-12-22 15:03 Balazs Fulop [this message]
2006-12-22 20:38 ` DNAT not working Grant Taylor
2006-12-22 21:14 ` Pascal Hambourg
2006-12-26 20:54 ` Balazs Fulop
-- strict thread matches above, loose matches on Subject: below --
2007-04-18 16:26 Payal Rathod
2007-04-18 17:34 ` Martijn Lievaart
2007-04-19 3:31 ` Payal Rathod
2007-04-19 11:15 ` Gáspár Lajos
2007-04-19 17:18 ` Payal Rathod
2004-07-12 15:12 DNAT Not working Nicolas Ross
2004-07-12 15:59 ` Antony Stone
2004-07-12 16:13 ` Nicolas Ross
2004-07-12 16:33 ` Antony Stone
2004-03-18 20:26 DNAT not working Stuart Lamble
2004-03-18 20:49 ` John A. Sullivan III
2004-03-18 21:58 ` Antony Stone
2004-03-18 20:50 ` Antony Stone
2004-03-20 17:47 ` Stuart Lamble
[not found] <20031224052809.18657.42710.Mailman@netfilter-sponsored-by.noris.net>
2003-12-24 10:24 ` DNAT NOT WORKING madhav bhasin
2003-12-24 10:33 ` Antony Stone
2003-12-25 18:31 ` Thomas Scheffczyk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=458BF3C2.4050700@initon.com \
--to=balazs.fulop@initon.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox