Welcome to the most active Linux Forum on the web.
Go Back > Forums > Linux Forums > Linux - Networking
User Name
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.


  Search this Thread
Old 08-05-2007, 04:23 AM   #1
LQ Newbie
Registered: Jan 2007
Location: Arkansas
Distribution: Zenwalk as desktop, Zenlive as router, XP as game box
Posts: 19

Rep: Reputation: 0
incoming connections with iptables

Lets say I have and behind a router and that router is connected to eth0 on a linux box whose ip is eth1 on that linux box is an address assigned to me by the isp. Here's a little diagram:

/ \
0 1
I currently have iptables on that linux box configured like this:

#iptables -F; iptables -t nat -F; iptables -t mangle -F
#iptables -t nat -A POSTROUTING -j SNAT --to $assignedIP

(taken straight from ipmasquerading-simple of the HOWTOS)

This has been working fine, as long as the connections originate from the internal network (from eth0 of the linux box). What I want to know is how can I configure the linux box to accept incoming connections and transfer them to.. lets say
Old 08-05-2007, 05:41 AM   #2
Registered: Sep 2006
Location: Munich, Germany
Distribution: Debian / Ubuntu
Posts: 297

Rep: Reputation: 49
First:, .101, .102 are all on the same subnet, but .102 is on a different physical network. This shouldn't work at all.

Originally Posted by willyweedle
#iptables -t nat -A POSTROUTING -j SNAT --to $assignedIP
This rule is applied to any packet, regardless of interface it comes in / goes out through or address it comes from / goes to. Is this really what you are using?

As to your question: What you are looking for is port forwarding. Add a PREROUTING rule to DNAT the packets and add a FORWARD rule to allow those packets through, e.g. to forward www:
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j DNAT --to
iptables -A FORWARD -i eth1 -p tcp --dst --dport 80 -j ACCEPT
Old 08-05-2007, 02:33 PM   #3
LQ Newbie
Registered: Jan 2007
Location: Arkansas
Distribution: Zenwalk as desktop, Zenlive as router, XP as game box
Posts: 19

Original Poster
Rep: Reputation: 0
Thanks! Things are working like I want them to now, and yes, that's really how I have iptables configured.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Is there a way to queue incoming sftp connections? erktrek Linux - Server 4 11-10-2006 02:06 PM
Listening for incoming connections vital_101 Mandriva 9 09-20-2005 08:26 PM
Discovering the true IP of incoming connections fibbi Linux - Networking 2 06-14-2005 01:46 AM
restricting incoming connections, using sockets SoulSkorpion Programming 2 10-20-2004 03:15 AM
Sendmail and incoming connections mike_smith Linux - Networking 3 01-19-2004 06:05 PM > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:55 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration