Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Leonardo Carneiro <lscarneiro@veltrac.com.br>
To: netfilter@vger.kernel.org
Subject: access problem
Date: Mon, 16 Mar 2009 16:41:05 -0300	[thread overview]
Message-ID: <49BEAB51.9070406@veltrac.com.br> (raw)

Hi everyone.

I'm new in the list and hope have a nice time here.
First of all, sorry about my poor enlgish, i'm from Brasil.

I've got a standard scenario with a private network (192.168.1.0/24) 
beeing natted by a internet server (192.168.1.1) running iptables 1.3.0.

In the private network I have a application server (192.168.1.2) running 
a service on port 5222. The port is properly forwarded in internet 
server, and users across the internet can access the service through the 
public IP of the internet server.

Users on the private network can access the service through the private 
IP of the server, but cannot access using the public ip. Accessing using 
the public ip would be very usefull, since lots of users have notebooks 
and they access the service inside and outside the private network

those are interface infos and the rules forwarding the port to the 
application server:
eth0: public IP
eth1: private network, 192.168.1.1

iptables -A PREROUTING -p tcp -m tcp -d [private_ip] -i eth0 --dport 
5222 -j DNAT --to-destination 192.168.1.2
iptables -A FORWARD -p tcp -m tcp -d 192.168.1.2 -i eth0 -o eth1 --dport 
5222 -j ACCEPT

I've done some tests, adding some rules like

iptables -A PREROUTING -p tcp -m tcp -d [private_ip] -i eth1 --dport 
5222 -j DNAT --to-destination 192.168.1.2
iptables -A FORWARD -p tcp -m tcp -d 192.168.1.2 -i eth0 -o eth1 --dport 
5222 -j ACCEPT

or just

iptables -A PREROUTING -p tcp -m tcp -d [private_ip] -i eth1 --dport 
5222 -j DNAT --to-destination 192.168.1.2

but i just cannot connect using the public ip =S

sometimes the server answer the request, but using the private ip, no 
the public ip requested by the host, and sometimes the server just not 
answer the request.

any ideas how can i solve this?

tks in advance.



             reply	other threads:[~2009-03-16 19:41 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-03-16 19:41 Leonardo Carneiro [this message]
  -- strict thread matches above, loose matches on Subject: below --
2009-03-17 17:23 access problem Leonardo Carneiro
2009-03-18 11:26 ` Brian Austin - Standard Universal
2009-05-26 13:20   ` Leonardo Carneiro

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=49BEAB51.9070406@veltrac.com.br \
    --to=lscarneiro@veltrac.com.br \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox