-   Linux - Networking (
-   -   iptables: preroute outgoing packets from tun0 to eth0 ? (

malo_umoran 09-20-2010 12:35 PM

iptables: preroute outgoing packets from tun0 to eth0 ?
I have a strange problem.

I have ssh daemon running on my server (, eth0).
Default gateway all traffic is (my router).
Router has a public ip and port 22222 is forwarding everything to my server ( on port 22.

That is nothing special.
I just set port when I want to connect to my server from outside:

ssh -p22222 user@

When I connect to a VPN server I get on tun0 device IP (tun0). Default gateway is being changed to and only connections to are going through

That is absolutely OK because I want all connections to go through VPN.

This is where the problem begins:
When I now try to connect from outside (i.e. to my server by using the above command connection is not being established. iptables log gave me the explanation:

1. incoming packets for server connection are coming through eth0

2. but outgoing packets from my server to are going through VPN gateway (, tun0) (because that is default gateway when VPN connection is active)

Any ideas how could I solve this? I could set one more route for IP to force it to go through eth0 but is a dynamic IP which I get on my 3G connection on my notebook.

I was thinking about prerouting/post outgoing packets on tun0 for port 22 to eth0 but I was not able to find anything for that in iptables. Is it even possible to solve it like that?

Could I maybe somehow add route on first incoming packet for this IP and delete it when the connection is gone?

Or is there some much elegant solution?


malo_umoran 09-20-2010 04:11 PM

OK, I was thinking too complicated. I made a ssh tunnel to my server:


ssh -fN -p22 root@ -L 22222:
and than I connect locally:


ssh -p22222 user@localhost

That is working pretty OK but is not a solution I like:
1. I have to keep open SSH port on my router
2. I have to connect twice (router + server)

So back to my original question: Is there a way to somehow force a service or iptables rule to a specific gateway?

malo_umoran 09-22-2010 02:35 AM

Nobody has other ideas?

All times are GMT -5. The time now is 12:17 AM.