LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-08-2011, 07:51 AM   #1
shorif2000
LQ Newbie
 
Registered: Mar 2011
Posts: 13

Rep: Reputation: 0
shorewwall forwad public vip to private vip on same box


hi,

I am having problems forwarding from public vip to private vip and back

configuration files

interfaces
Code:
#ZONE	INTERFACE	BROADCAST	OPTIONS
net     eth5            detect          
loc     bond0           detect
policy
Code:
#SOURCE	DEST	POLICY		LOG	LIMIT:		CONNLIMIT:
#				LEVEL	BURST		MASK
loc	all	ACCEPT
net	all	ACCEPT		
fw	all	ACCEPT		
#fw	net	ACCEPT		
#all	fw	ACCEPT		

# THE FOLLOWING POLICY MUST BE LAST
all	all	DROP		info
#$FW	net	ACCEPT
rules
Code:
#ACTION		SOURCE		DEST		PROTO	DEST	SOURCE		ORIGINAL	RATE		USER/	MARK	CONNLIMIT	TIME
#							PORT	PORT(S)		DEST		LIMIT		GROUP
#SECTION ESTABLISHED
#SECTION RELATED
#SECTION NEW

#ACCEPT loc all tcp 80 #not needed

#	Accept DNS connections from the firewall to the network
#
DNS(ACCEPT)	$FW		net
#
#	Accept SSH connections from the local network for administration
#
SSH(ACCEPT)	loc		all
SSH(ACCEPT)	net		all
SSH(ACCEPT)	$FW		all
#
#	Allow Ping from the local network
#
Ping(ACCEPT)	$FW		all
Ping(ACCEPT)	$FW		all
Ping(ACCEPT)	net		all


#
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
#

#Ping(DROP)	net		$FW

ACCEPT		$FW		all		icmp
ACCEPT		loc		all		icmp
ACCEPT		net		all		icmp



#ACCEPT      	net       	loc:192.168.0.237  tcp  80	-		195.171.205.21
#ACCEPT      	net       	loc:192.168.0.237  tcp  ssh	-		195.171.205.21


DNAT    	net     	loc:192.168.0.237  tcp  ssh,80,443			#works




ACCEPT fw net tcp 53     
ACCEPT fw net udp 53  
ACCEPT loc fw tcp 22
zones
Code:
#ZONE	TYPE		OPTIONS		IN			OUT
#					OPTIONS			OPTIONS
fw	firewall
net	ipv4
loc	ipv4
masq
Code:
eth5 bond0


In the above my public vip is 195.171.205.21, but i am using a real server ip (192.168.0.237) and it works. BUT if i use 192.168.0.199 which is the private vip on the same box it does not work.

Any help???
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Keepalived redirect public vip to private vip shorif2000 Linux - Networking 1 06-07-2011 10:33 AM
VIP listener_it Linux - Newbie 1 04-11-2011 01:00 PM
LVS - VIP Seems to be NOT Responding! justemail Linux - Networking 2 07-01-2009 03:13 AM
How to Define VIP in Suse Ilya Rabinovich Linux - Networking 1 09-25-2006 02:31 PM
VIP entry into any nightclub alexhen22 Linux - General 1 02-08-2006 11:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration