Linux Netfilter discussions
 help / color / mirror / Atom feed
From: ImpulseFG@netscape.net
To: netfilter@lists.netfilter.org
Subject: RE: SNAT interfering with source IP of a DNAT
Date: Wed, 05 Mar 2003 01:24:51 -0500	[thread overview]
Message-ID: <465F8149.1F5B7F36.0256A0D0@netscape.net> (raw)



The DNAT command looks good, but be careful, or you will end up routing, the ssh port to the 192.168.32.6 network and not be able to ssh in.

I thik the second command you want is $iptalbes -t nat -A PREROUTING -s 192.168.32.6 -j SNAT --to 10.10.10.8 . This will take all packets comming from 192.168.32.6 and make them look like they are coming from 10.10.10.8. 

The command you were using would make all teh packets coming from 172.17.0.0 subnet going to 192.168.32.12 . Look like they are coming from 192.168.32.6 . This would most likely get these packets lost, because the repling comuter 192.168.32.12 would send packets to 192.168.32.6 to reply instead of 172.17.0.0/19 . They would be lost.

>
>I've been beating my head against the table for the past couple of hours
>trying to get this working properly.
>
>I'm doing a PREROUTING DNAT that will send any traffic destined to
>10.10.10.8 and DNAT it to 192.168.32.12
>
>The DNAT works, but what keeps happening is the POSTROUTING rules further
>down the chain is changing the source IP to 192.168.32.6 instead of
>retaining the original source IP.
>
>What I need is the POSTROUTING SNAT rule to -ONLY- take place when an
>attempt to access 192.168.32.12 is established from anything else except
>the PREROUTING DNAT.
>
>here are the 2 PREROUTING and POSTROUTING entries:
>
>$IPT -t nat -A PREROUTING -d 10.10.10.8 -j DNAT --to 192.168.32.12
>
>...skip a bunch of other rules.
>
>$IPT -t nat -A POSTROUTING -s 172.17.0.0/19 -d 192.168.32.0/24 -j SNAT
>--to-source 192.168.32.6
>
>Right now, when I ssh to 10.10.10.8 it changes my source IP to
>192.168.32.6 because I'm coming from 172.17.3.24, but I'd like to avoid
>that unless I'm ssh'ing to 192.168.32.12 directly.
>
>The easiest thing to do would be to avoid the POSTROUTING SNAT but its a
>requirement I have to make sure anything going to 192.168.32.0/24 gets
>nat'ed to 192.168.32.6
>
>Any ideas of how to get around this ?
>
>Thanks.
>
>
>

__________________________________________________________________
The NEW Netscape 7.0 browser is now available. Upgrade now! http://channels.netscape.com/ns/browsers/download.jsp 

Get your own FREE, personal Netscape Mail account today at http://webmail.netscape.com/


             reply	other threads:[~2003-03-05  6:24 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-03-05  6:24 ImpulseFG [this message]
2003-03-05  6:39 ` SNAT interfering with source IP of a DNAT Steve Mickeler
  -- strict thread matches above, loose matches on Subject: below --
2003-03-05  2:18 Steve Mickeler

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=465F8149.1F5B7F36.0256A0D0@netscape.net \
    --to=impulsefg@netscape.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox