Networking Forums

Networking Forums > Computer Networking > Linux Networking > iptables-save using SNAT for machines behind firewall

Reply
Thread Tools Display Modes

iptables-save using SNAT for machines behind firewall

 
 
bl8n8r
Guest
Posts: n/a

 
      05-11-2007, 09:15 PM
# Generated by iptables-save v1.3.1 on Fri May 11 16:03:48 2007
*filter
:INPUT ACCEPT [4:727]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [11790:16610612]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 10.10.10.0/255.255.255.0 -d 10.10.10.0/255.255.255.0 -j
ACCEPT
-A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j
ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -p tcp -m tcp --dport 80 -m state --state
NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -s 10.10.10.0/255.255.255.0 -d 10.10.10.0/255.255.255.0 -j
ACCEPT
COMMIT
# Completed on Fri May 11 16:03:48 2007
# Generated by iptables-save v1.3.1 on Fri May 11 16:03:48 2007
*nat
:PREROUTING ACCEPT [4:765]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A PREROUTING -d 192.22.23.10 -p tcp -m tcp --dport 65022 -j DNAT --to-
destination 10.10.10.2:22
-A PREROUTING -d 192.22.23.10 -p tcp -m tcp --dport 80 -j DNAT --to-
destination 10.10.10.2:80
-A POSTROUTING -s 10.10.10.0/255.255.255.0 -o eth1 -p tcp -j SNAT --to-
source 192.22.23.10
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Fri May 11 16:03:48 2007

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Selective SNAT using IPtables? Justin Todd Linux Networking 2 12-16-2005 04:36 AM
iptables/SNAT not working Steffen Koepf Linux Networking 2 02-03-2005 11:26 AM
iptables SNAT & DNAT won't accept name Ming-Ching Tiew Linux Networking 2 10-08-2004 07:37 AM
iptables firewall/SNAT Cronus Linux Networking 2 12-13-2003 03:44 AM
iptables SNAT question (+) Den Linux Networking 0 10-28-2003 09:49 AM



1 2 3 4 5 6 7 8 9 10 11