Re: iptables using MASQUERADE and static IPs

From: Martin Cooper (usenet_at_martinc.me.uk)
Date: 05/30/03

  • Next message: Duane Arnold: "Re: BlackICE PC Protection Software"
    Date: Thu, 29 May 2003 23:10:59 +0100
    
    

    G. Artim wrote:
    <snip>
    > # setup Masquerqading
    > /sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

    Hi,
        change the above line to :-

            /sbin/iptables -A POSTROUTING -t nat -s 192.168.1.0/24 -o
    eth0 -j SNAT --to-source $SRCIP

    where $SRCIP is the real fixed IP address to be used for all traffic
    to / from your boxes with private IP's. This change will make iptables
    only mangle outgoing traffic from your private IP's, so traffic from
    any real IP's on your network will pass through unaffected. Of
    course, you will also need to block any unwanted traffic to these
    machines in the FORWARD chain.

        Martin


  • Next message: Duane Arnold: "Re: BlackICE PC Protection Software"

    Relevant Pages

    • Re: iptables using MASQUERADE and static IPs
      ... where $SRCIP is the real fixed IP address to be used for all traffic ... to / from your boxes with private IP's. ...
      (comp.security.misc)
    • Re: iptables using MASQUERADE and static IPs
      ... where $SRCIP is the real fixed IP address to be used for all traffic ... to / from your boxes with private IP's. ...
      (comp.os.linux.security)
    • Re: private psychiatrist
      ... [snip snip] ... I want a refund of my fees and ... You would have more rights if you had seen him on the NHS. ... There's a few things I would like to ask in private. ...
      (uk.legal)
    • Re: Looking for partners in US
      ... Systems was taken private in the summer of 2005, senior managers ... Shareholders beg, literally BEG, for these things and managers have genuine risk. ...
      (alt.machines.cnc)
    • Re: Looking for partners in US
      ... Wall Street's finest legal minds, ... Systems was taken private in the summer of 2005, ... Unka' George [George McDuffee] ...
      (alt.machines.cnc)