Visit Jeremy's Blog.
Go Back > Forums > Linux Forums > Linux - Networking
User Name
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.


  Search this Thread
Old 08-26-2003, 04:23 PM   #1
Registered: Nov 2000
Location: england
Distribution: latest Mandrake
Posts: 368

Rep: Reputation: 30
External port forwarding to an internal host


tonight i have one success story and one question
a few moments ago i successfully forwarded a citrix ica connection over the internet to an internal server on my companies network ( ), using a modified version of the line below:

iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination

we have two of these citrix deeleys and i would like to enable external access for the other server too, however the port is already inuse on the first external ip, so i thaught i would use the second ip address, my question is this:

how would i get linux to reconise connections to ip address 111.222.333.444 to go to citrix server 1 and 444.333.222.111 to go to server 2?

would i just stick in an extra option to iptables i.e.:
iptables -t nat -A PREROUTING -s 444.333.222.111 -p tcp --dport 1494 -j DNAT --to-destination

would that work, and just keep replacing the -s option with other ips?

Old 08-26-2003, 09:29 PM   #2
Registered: Aug 2001
Location: Off the coast of Madadascar
Posts: 498

Rep: Reputation: 30
Well if the source is always the same for which contact the same citrix metaframe. The you can say if the source is xyz goto this server, but if its abc goto this one. Or if you want to be at whatver computer you want and be able to get to either of them then you can set up that one gateway inteface (ex. eth0) to respond to 2 IPs.

ipconfig eth0:0 <IP address1> netmask <netmask> up
ipconfig eth0:1 <IP address2> netmask <netmask> up

Then you can rules like this:

iptables -t nat -i eth0:0-A PREROUTING -p tcp --dport 80 -j DNAT --to-destination
iptables -t nat -i eth0:1 -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination

So all you have to to do is point to either of the two IPs and you can access whichever server you want. Thats assuming you have 2 IPs availe which might be an issue if this a publicly accessible interface.

Old 12-17-2006, 08:01 AM   #3
LQ Newbie
Registered: Jul 2006
Posts: 11

Rep: Reputation: 0
External port forwarding

I just changed router from U.S.Robitics to Linksys WRT54G.
To excess my Linux server remotely (via PUTY) I forwarded external port 2222 to internal port 22 for LAN server in the U.S.Robotics router.

There don't seem to be such a posibility(at least I can't find it) in the Linksys router.

Is there another way (Linux way ?) to forward external port 2222 to internal port 22 ??

Old 12-17-2006, 09:43 AM   #4
Registered: Sep 2005
Location: New delhi
Distribution: RHEL 3.0/4.0
Posts: 777

Rep: Reputation: 31
Originally Posted by henkoegema
Is there another way (Linux way ?) to forward external port 2222 to internal port 22 ??
Henk you have yourself answered to this query in your first post with..
iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination
(you only got to change the ports of --dport 2222 & --to-destination X.X.X.X:22)

& if in case this the linux local router box, then you can use the REDIRECT handle in PREROUTING chain for the respective functionality.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Smoothwall selective forwarding from the same port to different internal computers jimdaworm Linux - Networking 4 03-16-2005 01:44 PM
allow tcp port 139 on internal, dmz and/or external geodo Linux - Newbie 1 11-23-2004 03:04 AM
Port Forwarding not working for Internal requests angelgw Linux - Networking 2 06-29-2003 12:42 AM
IPTABLES port forwarding to internal network ivanros Linux - Networking 2 12-28-2002 10:19 PM
Port forwarding to internal machine zamzara Linux - Networking 8 12-01-2002 12:21 AM > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:43 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration