IPTABLES How to access to web server on gateway from LAN?
Linux - NetworkingThis forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
[SOLVED] IPTABLES How to access web server on gateway from LAN?
Hi,
I configured Iptables (masquerading) and a Zope server on an old PII with 2 NIC cards running Arch Linux, making it my LAN gateway.
Everything runs fine so far, with SSH access to the server from LAN
Now I just can't figure out how may I get access to the zope site on the server from LAN :
neither public IP nore LAN's server/gateway IP are accessibles from the LAN Sad
IPTABLES config for the LAN (eth1) looks like this :
Code:
iptables -A INPUT -i eth1 -j ACCEPT
iptables -A OUTPUT -o eth1 -j ACCEPT
I need access to the zope portal as I'm its administrator
Since you can access the gateway box over SSH from the local network, the problem is probably with the Zope configuration.
I have NO EXPERIENCE with Zope, but...
Is the service bound to all interfaces or just the WAN port? I had a similar probem with Apache HTTPd - I was the only person in the world that couldn't connect to it - I got eth0 and eth1 IPs mixed up!
As for Zope (I'm talking about this server as well as the previous version that was running on my desktop PC), I tell it to listen on local IP. 'cause if i tell it to listen on my external IP, it fail to answer any request.
Same thing happens if I make it runs on my desktop PC (GW NATing external requests to it).
Now, as you pointed it out, it might be different when Zope runs on a gateway, but this is unclear to me !
PS : note that Peter Harrison says on his excellent iptables page :
Quote:
As a general rule, you won't be able to access the public NAT IP addresses from servers on your home network. Basic NAT testing requires you to ask a friend to try to connect to your home network from the Internet.
The Zope service is set up to listen on a local IP address, with NAT doing port-forwarding to allow external access to it.
You won't be able to access the service from the LAN using the public IP address, but you should be able to acces it using the local IP address. Try using the local IP address rather than a domain name when you connect.
If that works then you just need to sort out local DNS. A quick solution is to put an entry in your /etc/hosts to override external DNS. (check /etc/nsswitch.conf also)
Well, actually Zope was configured to listen to 'localhost' IP since that worked (from outside as well as locally) fine when it runned on my Desktop PC.
Now when i installed it on the gateway PC, I first configured it to listen to my ISP's provided IP, but it didn't run this way, so i renned back & told it to listen to 127.0.0.1 as before...
... until I made a better iptables configuration !
I just tried again :
- tell Zope to listen to my ISP's provided IP,
- try to access it from my desktop PC
and that just runs fine
The problem here was an uncomplete iptables configuration, then a wrong configuration of the web server.
Thank you DaveG for helping me to solve my problem
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.