LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-01-2003, 12:24 PM   #1
tsweatt
LQ Newbie
 
Registered: Sep 2003
Posts: 2

Rep: Reputation: 0
Route all traffic of a given type to an interface


Hello all.

I'm running Shorewall 1.3.11 on a box with 3 NICs. One NIC is connected to our cable modem (WAN), one to our campus network (LAN) and a third one is our psuedo-DMZ (I say psuedo because the machines in that zone are really just there so they are accessible from the net [webservers] and can selectively use each connection)

I want to route all http traffic to use eth1 (the LAN), leaving the cable bandwidth open for more specialized things. I've tried setting up a variety of rules, but I can't seem to find the right one. I've been successful in mapping MS Terminal Services through to the right machines and ports, so I know I'm not completely ignorant.

Here are the current rules :

#result client server proto port client_port address
ACCEPT fw wan tcp 53 -
ACCEPT fw wan udp 53 -
ACCEPT dmz wan udp 53 -
REJECT lan wan udp 53 -
ACCEPT lan fw tcp 22 -
DNAT:info lan dmz:192.168.1.87:80 tcp 87 -
DNAT:info wan dmz:192.168.1.87:80 tcp 87 -
ACCEPT lan fw tcp 8443 -
ACCEPT lan fw icmp 8 -
ACCEPT lan dmz icmp 8 -
ACCEPT dmz lan icmp 8 -
ACCEPT dmz fw icmp 8 -
ACCEPT fw dmz icmp 8 -
ACCEPT dmz lan tcp http -
ACCEPT lan wan tcp https -
ACCEPT lan wan tcp ssh -
ACCEPT lan wan tcp ftp -
ACCEPT lan wan tcp nntp -
ACCEPT fw wan udp ntp -
ACCEPT lan wan tcp imap -

The 2 DNAT rules redirect traffic that hits the WAN interface on port 87 to my webserver's port 80.

Is there a simple rule that could forward all DMZ -> any http traffic to the lan?

Thanks for any help.


(Oh, I know, having everything ACCEPT is probably a bad idea, but this is just for testing)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Need to route traffic through specific nic cards... Thaidog Linux - Networking 4 07-01-2005 07:31 PM
Need help to route traffic properly with 2 eth cards mchan Linux - Networking 1 03-20-2005 07:55 PM
route traffic onto the net from a lan gateway ulto Linux - Networking 1 04-13-2004 08:54 PM
route any traffic between two NICs thirumala Linux - Networking 0 03-24-2004 05:54 PM
Route traffic like a hub atlesn Linux - Networking 2 03-21-2004 04:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration