Re: iptables configuration help
Robert Moonen <rmoonen-bzGI/[email protected]> Sat, 06 Nov 2004 17:57:29 +1100
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Message-ID | <[email protected]> |
> I have added two sub interfaces to the external ethernet interface of > Smoothwall. There are 2 machines on the internal LAN and I want them > to go out using the IP of the sub interface, i.e access the internet > using the exteral IP's. they should not have any restrictions by > Smoothwall. How can do this and what IP Tables rules should I add ? > Hi Vijay It seems to me that all you really need to do is put in an ORANGE interface on whatever IP, I don't know why you would want to use different IP subnets on those two machines, but if just one subnet is OK, then set up ORANGE as that subnet address and voila, you have it. > I have done the following : > > iptables -A INPUT -s 172.16.0.119 -d 0.0.0.0/0.0.0.0 -j ACCEPT > iptables -I FORWARD -s 172.16.0.119 -j ACCEPT iptables -t nat -I > POSTROUTING -s 172.16.0.119 -o eth1:0 -j SNAT --to-source > <external_ip> > > When I addded the rules iptables gave me an error stating :" Weird > character in interface eth0:0, no ! : " Where am I going wrong ? Are > sub interface allowed in iptables ? -- regards Robert G. Moonen registered Linux user number 298132 There's only two infinite things: The universe and human stupidity, but I'm not sure about the first one. Albert Einstein _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall