LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-31-2011, 06:53 PM   #1
edotom
LQ Newbie
 
Registered: Apr 2004
Location: Colombia
Distribution: redhat
Posts: 2

Rep: Reputation: 0
simple Iptables. Linux receives internet but can reroute to computer in router


Hi
i have the following scenario.
I have an Isp which provides me internet which I receive on my ubuntu 11 box on my eth0. I share internet to my router using eth1 which has 10.10.10.1 / 255.255.255.0 with gateway 0.0.0.0 So far so good. All computers in my lan have internet. I have my svn working on my linux and all of my computers can reach to it. The problem. My pcs are on 192.168.1.0 and I can't get to redirect http 8080 to one of them. It was working with firestarter until I had to reinstall my former ubuntu 10 to ubuntu 11. I tried a lot of stuff with no luck.

Please take a pick at my iptables:

# Generated by iptables-save v1.4.10 on Mon Oct 31 18:41:48 2011
*nat
:PREROUTING ACCEPT [34:2544]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [4:197]
:POSTROUTING ACCEPT [3:132]
-A PREROUTING -i eth0 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.5:80
-A PREROUTING -i eth0 -p tcp -m tcp --dport 3690 -j DNAT --to-destination 10.10.10.1:3690
-A PREROUTING -i eth0 -p udp -m udp --dport 3690 -j DNAT --to-destination 10.10.10.1:3690
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Mon Oct 31 18:41:48 2011
# Generated by iptables-save v1.4.10 on Mon Oct 31 18:41:48 2011
*mangle
:PREROUTING ACCEPT [122:9281]
:INPUT ACCEPT [33:2279]
:FORWARD ACCEPT [85:6758]
:OUTPUT ACCEPT [29:2121]
:POSTROUTING ACCEPT [93:7115]
COMMIT
# Completed on Mon Oct 31 18:41:48 2011
# Generated by iptables-save v1.4.10 on Mon Oct 31 18:41:48 2011
*filter
:INPUT DROP [22:1716]
:FORWARD DROP [0:0]
:OUTPUT DROP [21:1764]
:INBOUND - [0:0]
:LOG_FILTER - [0:0]
:LSI - [0:0]
:LSO - [0:0]
:OUTBOUND - [0:0]
-A INPUT -s 200.75.51.132/32 -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A INPUT -s 200.75.51.132/32 -p udp -j ACCEPT
-A INPUT -s 200.75.51.133/32 -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A INPUT -s 200.75.51.133/32 -p udp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -m limit --limit 10/sec -j ACCEPT
-A INPUT -d 255.255.255.255/32 -i eth0 -j DROP
-A INPUT -d 190.24.226.47/32 -j DROP
-A INPUT -s 224.0.0.0/8 -j DROP
-A INPUT -d 224.0.0.0/8 -j DROP
-A INPUT -s 255.255.255.255/32 -j DROP
-A INPUT -d 0.0.0.0/32 -j DROP
-A INPUT -m state --state INVALID -j DROP
-A INPUT -f -m limit --limit 10/min -j LSI
-A INPUT -i eth0 -j INBOUND
-A INPUT -d 10.10.10.1/32 -i eth1 -j INBOUND
-A INPUT -d 190.24.226.46/32 -i eth1 -j INBOUND
-A INPUT -d 10.10.10.255/32 -i eth1 -j INBOUND
-A INPUT -d 192.168.1.6/32 -i eth2 -j INBOUND
-A INPUT -j LOG_FILTER
-A INPUT -j LOG --log-prefix "Unknown Input" --log-level 6
-A FORWARD -d 192.168.1.5/32 -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A FORWARD -p icmp -m limit --limit 10/sec -j ACCEPT
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -d 10.10.10.1/32 -i eth0 -p tcp -m tcp --dport 3690 -j ACCEPT
-A FORWARD -d 10.10.10.1/32 -i eth0 -p udp -m udp --dport 3690 -j ACCEPT
-A FORWARD -i eth1 -j OUTBOUND
-A FORWARD -d 10.10.10.0/24 -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.10.10.0/24 -p udp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j LOG_FILTER
-A FORWARD -j LOG --log-prefix "Unknown Forward" --log-level 6
-A OUTPUT -s 190.24.226.46/32 -d 200.75.51.132/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -s 190.24.226.46/32 -d 200.75.51.132/32 -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -s 190.24.226.46/32 -d 200.75.51.133/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -s 190.24.226.46/32 -d 200.75.51.133/32 -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -s 224.0.0.0/8 -j DROP
-A OUTPUT -d 224.0.0.0/8 -j DROP
-A OUTPUT -s 255.255.255.255/32 -j DROP
-A OUTPUT -d 0.0.0.0/32 -j DROP
-A OUTPUT -m state --state INVALID -j DROP
-A OUTPUT -o eth0 -j OUTBOUND
-A OUTPUT -o eth1 -j OUTBOUND
-A OUTPUT -j LOG_FILTER
-A OUTPUT -j LOG --log-prefix "Unknown Output" --log-level 6
-A INBOUND -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INBOUND -p udp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INBOUND -p tcp -m tcp --dport 22 -j ACCEPT
-A INBOUND -p udp -m udp --dport 22 -j ACCEPT
-A INBOUND -p tcp -m tcp --dport 3690 -j ACCEPT
-A INBOUND -p udp -m udp --dport 3690 -j ACCEPT
-A INBOUND -p tcp -m tcp --dport 80 -j ACCEPT
-A INBOUND -p udp -m udp --dport 80 -j ACCEPT
-A INBOUND -p tcp -m tcp --dport 5900 -j ACCEPT
-A INBOUND -p udp -m udp --dport 5900 -j ACCEPT
-A INBOUND -j LSI
-A LSI -j LOG_FILTER
-A LSI -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 1/sec -j LOG --log-prefix "Inbound " --log-level 6
-A LSI -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
-A LSI -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j LOG --log-prefix "Inbound " --log-level 6
-A LSI -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -j DROP
-A LSI -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j LOG --log-prefix "Inbound " --log-level 6
-A LSI -p icmp -m icmp --icmp-type 8 -j DROP
-A LSI -m limit --limit 5/sec -j LOG --log-prefix "Inbound " --log-level 6
-A LSI -j DROP
-A LSO -j LOG_FILTER
-A LSO -m limit --limit 5/sec -j LOG --log-prefix "Outbound " --log-level 6
-A LSO -j REJECT --reject-with icmp-port-unreachable
-A OUTBOUND -p icmp -j ACCEPT
-A OUTBOUND -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTBOUND -p udp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTBOUND -j ACCEPT
COMMIT
# Completed on Mon Oct 31 18:41:49 2011

I'm in despair.

regards

edotom
 
Old 11-01-2011, 12:48 AM   #2
lqman
LQ Newbie
 
Registered: Nov 2010
Location: Surabaya, Indonesia
Distribution: debian, ubuntu, FreeBSD, Solaris
Posts: 17

Rep: Reputation: 3
What is your eth0 ip address? it is static or dynamic?
Where is your PC 192.168.1.5 position regarding ilustration below?

{internet from ISP}-----[eth0:?]{ubuntu}[eth1:10.10.10.1/24]-----{LAN}
 
Old 11-01-2011, 01:16 AM   #3
ceyx
Member
 
Registered: May 2009
Location: Fort Langley BC
Distribution: Kubuntu,Free BSD,OSX,Windows
Posts: 342

Rep: Reputation: 59
Line 5 ...

-A PREROUTING -i eth0 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.5:80

should be

-A PREROUTING -i eth0 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.5:8080

??
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Need Help on Simple IPTables Router/Firewall dmlinton Linux - Networking 2 09-11-2010 10:00 AM
IPTables Reroute Outing Traffic Through VPN Usogi Linux - Networking 6 04-11-2008 01:29 AM
iptables on router: simple port forwarding not working hamish Linux - Networking 1 10-27-2005 06:06 AM
Considering Mac Mini for people who use computer for simple internet use linux-rulz Other *NIX 3 01-16-2005 06:38 AM
My laptop receives an IP via DHCP, but can't ping router or outside IP's! Max P0wer Linux - Networking 12 08-17-2004 05:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration