[fw-wiz] Nat+Port Forwarding

From: Martin Schoeman (martin@i-online.co.za)
Date: 03/14/03

  • Next message: Amiel David: "Re: [fw-wiz] Nat+Port Forwarding"
    From: "Martin Schoeman" <martin@i-online.co.za>
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 14 Mar 2003 10:03:24 +0200
    

    Hi

    I have a W2K server on my internal LAN xxx.xxx.xxx.xxx (private ip) I
    am using iptables and need to connect from the outside to the W2K
    server using MS Terminal Service. I need to open and forward port 3389
    TCP and UDP for this to work as far as I know

    This is what I came up with so far.

    *nat -A PREROUTING -p tcp -m tcp --dport 3389 -j DNAT --to-destination
    xxx.xxx.xxx.xxx -A POSTROUTING -o eth0 -j SNAT --to-source
    yyy.yyy.yyy.yyy(servers external card) p --dport 3389 -j DNAT
    --to-destination xxx.xxx.xxx.xxx

    *filter -A FORWARD -p tcp -m tcp --dport 3389 -j ACCEPT -A FORWARD -p
    udp -m udp --dport 3389 -j ACCEPT -A INPUT -p tcp -m tcp -s 0/0
    --dport 3389 -j ACCEPT -A INPUT -p udp -m udp -s 0/0 --dport 3389 -j
    ACCEPT

    Any help would be much appreciated
    Martin Schoeman

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Amiel David: "Re: [fw-wiz] Nat+Port Forwarding"

    Relevant Pages

    • Re: Re[5]: Assymetric NIC performance problem
      ... I've got a FreeBSD file server running Samba, file upload speeds are okay, ... Client connecting to 192.168.0.1, TCP port 5001 ... Sorry, I didn't know that UDP bandwidth must be specified manually, ...
      (freebsd-net)
    • Re: ipfw and nmap
      ... > even be correct but I have a bsd box that is simply providing me SSH ... add allow tcp from any to me 22 setup in via fxp0 keep-state ... Note too that there is nothing to prevent port scanners simply setting ... the 'SYN' flag in the probe packets they send to your server. ...
      (freebsd-questions)
    • Re: SQL 2008 Remoteverbindung
      ... Ich kann mich jetzt auf den Server verbinden & es funktioniert wirklich ... die Grundsätzliche Verbindung funktioniert jetzt. ... Bei IPALL bist du schon richtig, den Port must du aber bei 'TCP Port' ...
      (microsoft.public.de.sqlserver)
    • Re: network programming: how does s.accept() work?
      ... The articles and books I've read all claim that the server ... port 5053 is a 'listening' port only. ... the server creates a new socket for communication between the client ... on the network, and in the RFCs which define the TCP protocol (UDP too, but ...
      (comp.lang.python)
    • Re: Why does DNS.EXE listen on a ephemeral TCP port?
      ... Right, but when my name server makes a query to another name server, and the ... server and then my server originates a TCP connection. ... local TCP port to a destination of TCP 53 on the server) I understand why ... In order for a TCP listening port to be ...
      (microsoft.public.windows.server.dns)