Linux Netfilter discussions
 help / color / mirror / Atom feed
* Regarding iptable rules for SNAT
@ 2011-10-18  3:42 Ajith Adapa
  2011-10-18  8:08 ` Marek Kierdelewicz
  2011-10-18 18:33 ` Erik Schorr
  0 siblings, 2 replies; 7+ messages in thread
From: Ajith Adapa @ 2011-10-18  3:42 UTC (permalink / raw)
  To: netfilter

Hi,

I have a following setup. GW eth1 (private ip) is connected to the ISP
router. For host H1 I have set the DNS server as 10.12.3.10.

H1 (eth0) --- (eth0) GW (eth1) ---
H1 eth0 = 192.168.1.2
GW eth0 = 192.168.1.1
GW eth1 = 10.12.3.12
DNS = 10.12.3.10

I have added a rule in GW saying iptables -A POSTROUTING -t nat -o
eth1 -j MASQUERADE

Now when I am trying to access internet from host H1, DNS queries are
being sent to 10.12.3.10 which are masqueraded in GW. Once replies
come back from DNS server then GW is replying back to DNS server with
icmp destination unreachable.

Ideal cases once the reply comes back GW has to send it to the host H1 right ?

Sorry if I am wrong or missed any steps down here ?

Regards,
Ajith

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2011-10-19 23:43 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-10-18  3:42 Regarding iptable rules for SNAT Ajith Adapa
2011-10-18  8:08 ` Marek Kierdelewicz
2011-10-19  3:16   ` Ajith Adapa
     [not found]     ` <CAA2qdGUphypn=RTRadM1Mt0bGGqquJv_fa_MRBzayZavPthX6A@mail.gmail.com>
2011-10-19  5:28       ` Ajith Adapa
2011-10-18 18:33 ` Erik Schorr
2011-10-19  3:16   ` Ajith Adapa
     [not found]   ` <CADAe=++EOD5mLsVO2o3W85uLo2DWxBsdeyn8b=6UT9w0OAPYMA@mail.gmail.com>
2011-10-19 23:43     ` Erik Schorr

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox