Routing internal ports back to LAN

"Christian Hack" <christianh-lIdDhfUXi0a6c6uEtOJ/[email protected]> Tue, 18 May 2004 08:11:15 +1000
Newsgroups gmane.linux.admin.managers
Organization EDMI
Message-ID <01f001c43c5b$e1480320$c701010a@PC>
I am trying to route the POP3/IMAP ports on my firewall to an internal
server.

Setup is eth0 is the Internet, eth1 is the LAN

Port mapping from outside the LAN (i.e. mapping ports 143 and 110 from eth0
to eth1) is no problem and works fine.

What I want to do is also map 143 and 110 from eth1 back on to the internal
LAN on eth1. You ask why don't I just connect directly? I have a number of
users who sometimes use the LAN and sometimes are external. I want to be
able to set up their mail with one host name accessible via the internet
_and_ the LAN which always works. Thus they always point at the firewall
which in turn routes them back to the internal server.

>From what I understand in Linux this is not normally possible, but I have
been told Snapgear routers (which run linux) can do this.

The one option I have found is a dual DNS setup where internally, I point
particular hosts directly to the internal LAN and externally I point those
hosts to the firewall. I'd like to be able to do it with port
forwarding/mapping if possible though.

Any ideas or is my DNS solution the only one? TIA.

Now that I have written this I have thought of another solution. I guess I
could do some LAN card trickery and either add another card (e.g. just route
from eth1 to eth2 both connected to the same LAN) or setup some kind of
multihomed setup on the internal LAN card.

CH
_______________________________________________
LinuxManagers mailing list - http://www.linuxmanagers.org
submissions: LinuxManagers-35TzE1X9F6582KRnZfj+bdi2O/[email protected]
subscribe/unsubscribe: http://www.linuxmanagers.org/mailman/listinfo/linuxmanagers