LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-09-2018, 07:09 AM   #1
ulaoulao
Member
 
Registered: Jul 2004
Posts: 36

Rep: Reputation: 15
ufw (firewall) not doing nat like it should?


I'm new to 18.04 and the new networking stuff. First thing that sort of confused me was the new labels enp2s0 instead of eth0. Assuming this is just a name, I set up my nat like so .

/etc/default/ufw

change

DEFAULT_FORWARD_POLICY="ACCEPT"

/etc/ufw/sysctl.conf

net.ipv4.ip_forward=1

and in my /etc/ufw/before.rules

*nat:

POSTROUTING ACCEPT [0:0]

#-A POSTROUTING -s 192.168.0.1/24 -o enp2s0 -j MASQUERADE#-A POSTROUTING -s enp3s5 -o enp2s0 -j MASQUERADE-A POSTROUTING -o enp2s0 -j MASQUERADECOMMIT

As you can see from the comments I tried a few ways.

enp3s5 is my intrAnet card
enp2s0 is my internet card

-------------------------------------------
This is what I did in 14.04
sudo modprobe iptable_nat
sudo iptables -t nat -A POSTROUTING -o eth3 -j MASQUERADE
sudo iptables -t mangle -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
echo 1 > /proc/sys/net/ipv4/ip_forward

eth3 was my intra and eth0 was internet

Did I do something wrong?

Last edited by ulaoulao; 08-09-2018 at 08:41 AM.
 
Old 08-09-2018, 08:26 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,085
Blog Entries: 28

Rep: Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086
enp2s0 is one of those laughingly mislabeled "predictable device names."
 
Old 08-09-2018, 08:35 PM   #3
ulaoulao
Member
 
Registered: Jul 2004
Posts: 36

Original Poster
Rep: Reputation: 15
agreed but seemingly not helpful LOL

Anyways I ripped out netplan and used the old network/interfaces. That works.
 
Old 08-09-2018, 08:56 PM   #4
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,085
Blog Entries: 28

Rep: Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086Reputation: 6086
I reread your first post.

Maybe I'm just being dim tonight, but I'm not sure what your firewall is doing that you don't want it to do or not doing that you want it to do.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
UFW firewall setup Arzach Linux - Server 7 09-05-2016 11:14 AM
[SOLVED] Can't install ufw firewall Gregg Bell Linux - Software 3 03-13-2014 12:11 AM
question about firewall ufw marco1965 Linux - Server 4 08-12-2013 09:58 AM
ufw firewall rhlnewbie Linux - Software 2 10-18-2009 04:23 PM
LXer: Ubuntu 9.10 UFW Firewall LXer Syndicated Linux News 0 10-15-2009 02:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration