NAT(MASQ) and default policies on a dynamic ip interface

From: Andreas Gredler (andreas.gredler_at_g-tec.co.at)
Date: 08/28/03


Date: 28 Aug 2003 04:02:13 +0200

Hello,

I'm running a server which connects my LAN to the internet via
masquerading. Today I realized that all policies are set to ACCEPT.
Therefore I changed all to DROP, which had some drawbacks. My problem
are the rules for NAT, so that I can set it to DROP. My basic ruleset
was taken from the NAT-Howto:
iptables -A POSTROUTING -s 192.168.0.0/24 -o ppp0 -j MASQUERADE
But when I set the policy to DROP NAT still works, but not on the server
itself... due to the -s 192.168.0.0/24 part. I would also need to allow
localhost and my external ip, too.
But my external ip is dynamic and I'm looking for another way to solve
the problem. Would be easy to read the external interface ip with the
help of ifconfig and awk but that would mean, that the whole ruleset
has to be reloaded after reconnecting my WAN interface.

Any help much appreciated.

greets Jimmy

-- 
Andreas "Jimmy" Gredler, andreas.gredler@gmx.at
Get my public key at www.g-tec.co.at


Relevant Pages

  • Re: External interface on Exchange 2003
    ... the router once it's done. ... Exchange 5.5 in the environment. ... move everything over to the new server. ... up to the external interface is forwarding everything to the W2k box (I ...
    (microsoft.public.exchange.admin)
  • Re: How to establish connections to the servers inside a DMZ?
    ... > external interface, what in the world is going to make the ... This makes this Linux box a router rather than just a leaf ... > SERVER.DOMAIN.com in order to interact with the correct server. ... The GW/firewall should similarly be trimmed of all excess software. ...
    (comp.os.linux.networking)
  • Re: External interface on Exchange 2003
    ... internet through the router. ... move everything over to the new server. ... From what I understand the router that is hooked ... up to the external interface is forwarding everything to the W2k box (I ...
    (microsoft.public.exchange.admin)
  • RE: Page cannot be displayed in OWA
    ... 25 to the external interface of the server ... entire Web site from the Internet" is selected. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Access to server on internal network
    ... Hi, confirmed, but not in a production environement, it was in a test lab ... > as you server publish on both ISA Servers. ... then map PortX on the external interface of ISA2 to the server ...
    (microsoft.public.isa.configuration)