Re: DNAT PREROUTING issue with IPTABLES
|[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]|
Indunil Jayasooriya wrote:
> SECOND Firewall's default route (gateway) is NOT the FIRST firewall.
> BOTH firewall's default route (gateway) is the router given by our ISP.
Ok, so you understand your problem now?
Assuming the packet arrives at 18.104.22.168 from random external ip (eg.
22.214.171.124), is successfully dnat+rerouted to 126.96.36.199, there again
dnat+reroute to 192.168.x.x. Arrives at smtp server and smtp server
sends a reply to the original sender 188.8.131.52. It does that via it's
default gateway which I assume is 184.108.40.206. 220.127.116.11 sends it via your
ISP's gateway with it's own address of 18.104.22.168 to 22.214.171.124.
But 126.96.36.199 sent the packet 188.8.131.52, not 184.108.40.206, so it discards it.
And that's exactly what Riccardo said when I read his mail now.
The first problem though is that I'm not sure the dnat form 220.127.116.11 to
18.104.22.168 works, the packet would have to leave via the same interface it
came. Maybe this works, I've never tried that. Make sure packets arrive
on the smtp box with tcpdump.
As for the solution, one way would be to SNAT the connection at FW1, but
this wwould cause the smtp box to see as if all the incoming connections
are from 22.214.171.124 and not their real IP's (126.96.36.199).
Actually you should set up custom routing at 188.8.131.52 and not DNAT. You'd
have to mark the packets and then send them to the 184.108.40.206 fw via a
custom route. I'm not sure I could help you with that, never done any
+372 6659 649
LARTC mailing list
_______________________________________________ LARTC mailing list LARTC@xxxxxxxxxxxxxxx http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc