LinuxQuestions.org
Visit the LQ Articles and Editorials section
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Search this Thread
Old 06-12-2003, 12:57 PM   #1
angelgw
LQ Newbie
 
Registered: Jun 2003
Posts: 2

Rep: Reputation: 0
Angry Port Forwarding not working for Internal requests


Hi there,

I am trying to configure port forwarding on my server running Redhat 7.3. The idea is to forward requests to xxxx:8080 to 192.168.3.1:80. (xxxx is the static IP I have.) It works fine if I try to connect to xxxx:8080 from a computer outside of my LAN, but DOESN'T WORK inside my LAN. Of course, I can use 192.168.3.1 to load the page, which means the problem is solely with port forwarding. I definitely need to get this working because I have IP addresses in my HTML and other files, and I can't do testing if xxxx:8080 doesn't work in my LAN.

Anyone else having the same problem with Port Forwarding of requests from $INTIF? Any advice? Did I do something wrong or is it possible to do? Thanks. My port forwarding section of iptables.sh is attached below....

//Accept connections to port 8080
iptables -A INPUT -i $EXTIF -p tcp -d $EXTIP --dport 8080 -j ACCEPT
iptables -A OUTPUT -o $EXTIF -p tcp -s $EXTIP --sport 8080 ! --syn -j ACCEPT

//forwarding...
iptables -t nat -A PREROUTING -p tcp -i $EXTIF -d $EXTIP --dport 8080 -j DNAT --to 192.168.3.1:80
iptables -A FORWARD -p tcp -i $EXTIF -d 192.168.3.1 --dport 80 -j ACCEPT
//This doesn't work.....
iptables -t nat -A PREROUTING -p tcp -i $INTIF -d $EXTIP --dport 8080 -j DNAT --to 192.168.3.1:80
iptables -A FORWARD -p tcp -i $INTIF -d 192.168.3.1 --dport 80 -j ACCEPT
 
Old 06-28-2003, 11:36 AM   #2
dorian33
Member
 
Registered: Jan 2003
Location: Poland, Warsaw
Distribution: LFS, Gentoo
Posts: 587

Rep: Reputation: 32
1. You don't need use INPUT and OUTPUT chains. Is it not true you need them for accepting the packet sent to port 8080.
This is the big difference between ipchains & iptables. (with ipchains you need them).

2. Regarding your problem.
In more complex problem there is no way to present the solution seeing only few rules.... but I'll try to decribe the problem you probably met.
I assume you are using the box as router so somewhere you have a rule with SNAT or MASQUERADE target. It makes the packet leaving your system to have $EXTIP as the source address. It is done independently if it is sent to the "world" IP or $EXTIP.
As a result packets sent from internal boxes to $EXTIP port 8080 leaves your router with dest ip = 192.168.3.1 but src ip = $EXTIP.
And there is no rule for forwarding packets which are coming back (they are sent to $EXTIP!)
 
Old 06-29-2003, 12:42 AM   #3
angelgw
LQ Newbie
 
Registered: Jun 2003
Posts: 2

Original Poster
Rep: Reputation: 0
Yep, MASQUERADE is the problem. I have solved it now. Thanks.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
External port forwarding to an internal host antken Linux - Networking 3 12-17-2006 09:43 AM
port forwarding? not working?... snip128 Linux - Networking 1 10-07-2005 09:49 AM
Smoothwall selective forwarding from the same port to different internal computers jimdaworm Linux - Networking 4 03-16-2005 01:44 PM
IPTABLES port forwarding to internal network ivanros Linux - Networking 2 12-28-2002 10:19 PM
Port forwarding to internal machine zamzara Linux - Networking 8 12-01-2002 12:21 AM


All times are GMT -5. The time now is 11:39 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration