LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Search this Thread
Old 03-25-2010, 04:11 AM   #1
spangberg
LQ Newbie
 
Registered: Mar 2010
Posts: 3

Rep: Reputation: 0
Iptables - port forwarding to blocked port?


I have a mail server on which I would like to block port 25 on my eth0 for everyone except our external spam filter. the problem is that I want our users to be able to connect via port 10025 which is forwarded to port 25, which then is blocked...

How can I get this to work? Any ideas?

Thanks!
// Tomas
 
Old 03-25-2010, 04:35 AM   #2
centosboy
Senior Member
 
Registered: May 2009
Location: london
Distribution: centos5
Posts: 1,137

Rep: Reputation: 116Reputation: 116
Quote:
Originally Posted by spangberg View Post
I have a mail server on which I would like to block port 25 on my eth0 for everyone except our external spam filter. the problem is that I want our users to be able to connect via port 10025 which is forwarded to port 25, which then is blocked...

How can I get this to work? Any ideas?

Thanks!
// Tomas

1 option is to
run your mail daemon on port 10025 instead.
create iptables rules that redirect from 25 to 10025.

another is to run the daemon on both 25 and 10025. allow access to spam filter on 25 only and access to others on 10025.


some examples:

Code:
iptables -I INPUT -s spamfilter -p tcp -i eth0 --dport 25 -j ACCEPT
iptables -I PREROUTING -s spamfilter -t nat -p tcp -d x.x.x.x --dport 25 -j DNAT --to x.x.x.x:10025
iptables -I PREROUTING -s x.x.x.x -t nat -p tcp -d x.x.x.x --dport 25 -j DNAT --to x.x.x.x:10025
 
Old 03-26-2010, 05:48 AM   #3
spangberg
LQ Newbie
 
Registered: Mar 2010
Posts: 3

Original Poster
Rep: Reputation: 0
Thanks!

Worked with both options, now I just have to decide which one to to use...

// Tomas
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables port forwarding geoff3425 Slackware 13 12-20-2011 11:50 AM
I blocked SSH 22 port with IPtables seryi Linux - General 7 02-02-2010 08:43 PM
IPCHAINS port forwarding and IPTABLES port forwarding ediestajr Linux - Networking 26 01-14-2007 08:35 PM
port forwarding with iptables solletica Linux - Networking 5 03-12-2006 05:37 AM
Port 80 forwarding to port 22 with iptables zahoo Linux - Networking 3 02-22-2005 08:22 AM


All times are GMT -5. The time now is 08:46 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration