DNAT: forwarding all ports to a host

green <[email protected]>
Newsgroups gmane.linux.debian.devel.firewall
Message-ID <20100715175528.GG1683@swansys>
One requirement for a firewall setup I am working on is the ability to forward 
all (remaining) ports to a specific host on the network.  Note that I am hoping 
to avoid using this but it is required as an option.

The server/router runs some services.  There is a chain of RETURNs for those 
services.  Packets with the remaining destination ports fall through to the 
actual DNAT target:
# iptables -t nat -A PREROUTING -i eth0 -j DNAT --to-destination 192.168.2.10

But what affect does this have on ESTABLISHED,RELATED connections?  Does this 
interfere with, say, a reply from google.com:80 to network host 192.168.2.99?

Links etcetera welcome.

Thanks.
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkw/S48ACgkQ682C+dBP+oTx1wCePmMS4yhtXzpmoaqEraOAt340
bacAoK9GLOG1b0u+gh0B/xbRHo2WTS/m
=tDl1
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.