Linux Netfilter discussions
 help / color / mirror / Atom feed
* Does redirect in PREROUTING require open port in INPUT?
@ 2004-03-27 20:31 forum
  2004-03-27 20:50 ` Antony Stone
  0 siblings, 1 reply; 2+ messages in thread
From: forum @ 2004-03-27 20:31 UTC (permalink / raw)
  To: netfilter

My situation is, I run two different nameservers (one on udp 53 and another 
one on udp 5300). The one on the higher port is meant to be private and 
used only by permitted IPs.

Currently, I am using the following with success:
-----------------------
iptables -P INPUT DROP
iptables -A INPUT -i $EXTIF -p udp --dport 53 -j ACCEPT
iptables -A INPUT -i $EXTIF -p udp --dport 5300 -j ACCEPT

iptables -t nat -A PREROUTING -i $EXTIF -p udp --dport 53 -s 1.2.3.4 \
	-j REDIRECT --to-ports 5300
-----------------------

Works fine; only the IP 1.2.3.4 can access the private nameserver while all 
other public requests go to the default server on port 53. However I found 
that I needed to explicitly open up port 5300 on INPUT for this to work. 
While I could throw in an additional -s check in the INPUT rules, it seems 
like an ugly duplication if I have a large number of IPs.

Is there a more elegant way to do this port redirection without opening up 
the private port to the world? i.e. somehow see that a REDIRECT happened, 
rather than a packet actually coming in with destination port 5300?

-- 
forum@users.pc9.org




^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Does redirect in PREROUTING require open port in INPUT?
  2004-03-27 20:31 Does redirect in PREROUTING require open port in INPUT? forum
@ 2004-03-27 20:50 ` Antony Stone
  0 siblings, 0 replies; 2+ messages in thread
From: Antony Stone @ 2004-03-27 20:50 UTC (permalink / raw)
  To: netfilter

On Saturday 27 March 2004 8:31 pm, forum@users.pc9.org wrote:

> My situation is, I run two different nameservers (one on udp 53 and another
> one on udp 5300). The one on the higher port is meant to be private and
> used only by permitted IPs.
>
> Currently, I am using the following with success:
> -----------------------
> iptables -P INPUT DROP
> iptables -A INPUT -i $EXTIF -p udp --dport 53 -j ACCEPT
> iptables -A INPUT -i $EXTIF -p udp --dport 5300 -j ACCEPT
>
> iptables -t nat -A PREROUTING -i $EXTIF -p udp --dport 53 -s 1.2.3.4 \
> 	-j REDIRECT --to-ports 5300
> -----------------------
>
> Works fine; only the IP 1.2.3.4 can access the private nameserver while all
> other public requests go to the default server on port 53. However I found
> that I needed to explicitly open up port 5300 on INPUT for this to work.
> While I could throw in an additional -s check in the INPUT rules, it seems
> like an ugly duplication if I have a large number of IPs.
>
> Is there a more elegant way to do this port redirection without opening up
> the private port to the world? i.e. somehow see that a REDIRECT happened,
> rather than a packet actually coming in with destination port 5300?

I would recommend the use of split DNS.

Do it at the application layer instead of the network layer, then everything 
works on port 53.

Regards,

Antony.

-- 
If you want to be happy for an hour, get drunk.
If you want to be happy for a year, get married.
If you want to be happy for a lifetime, get a garden.

                                                     Please reply to the list;
                                                           please don't CC me.



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2004-03-27 20:50 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-27 20:31 Does redirect in PREROUTING require open port in INPUT? forum
2004-03-27 20:50 ` Antony Stone

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox