RE: [Security Firewall] Problem with port forwarding
"Jim" <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.firewall |
|---|---|
| Message-ID | <[email protected]> |
Ok, this changes everything. How are you passing the packets from the router to the firewall if the firewall is NATed? Is the router set to make x.x.10.254 the ROUTER's internal DMZ? What kind of router is it? From what I'm gathering your router isn't/can't pass packets from the external public interface to the internal natted firewall. Basically you need to set up your router so that it forwards ALL packets to the firewall. Let the firewall be the firewall, not the router. Jim -----Original Message----- From: security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected] [mailto:security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected]] On Behalf Of ibon M. B. Sent: Wednesday, June 15, 2005 3:27 PM To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] Subject: Re: [Security Firewall] Problem with port forwarding internet | | | (x.x.x.x- Public IP)Router(192.168.10.1 Internal IP) | | | (192.168.10.254 eth1)MNF(192.168.1.254 eth0) | | | LAN (192.168.1.0/24) >From: florin <[email protected]> >Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] >To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] >Subject: Re: [Security Firewall] Problem with port forwarding >Date: Wed, 15 Jun 2005 20:55:43 +0200 > >router, what router ... simply draw us an ascii map of your situation >to have a better idea ... > >On 6/15/05, ibon M. B. <[email protected]> wrote: > > the router is using NAT, i also had tried: > > DNAT wan lan:192.168.1.101 tcp ftp - public_ip > > > > and doesn´t work. > > i don´t know what i´m doing wrong:(( > > > > >Assuming your LAN is using NAT, none of these will work because you >have to > > >specify the public IP in the forward portion of the DNAT rule. (it > > >has >to > > >know where to listen) > > > > > >Here is a rule that we use to gain SSH into a linux box within the > > >lan >from > > >the wan (where xxx is your public IP) > > > > > >DNAT wan lan:192.168.69.3 tcp ssh - > > >xxx.xxx.xxx.xxx > > > > > >ftp and ftp-data would be the same. Be sure and remove those other >rules. > > >Jim > > > > > > >From: "ibon M. B." <[email protected]> > > >Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] > > >To: security-firewall-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org > > >Subject: [Security Firewall] Problem with port forwarding > > >Date: Tue, 14 Jun 2005 10:06:26 +0000 > > > > > >Thanks for your help > > >I have created a custom rule to forward the ftp traffic to a > > >computer >in my > > >lan, but port forwarding doesn´t seem to work. > > >Custom Rule: > > >Result --DNAT > > >Predefined Services--FTP > > >Protocol--FTP > > >Client:WAN > > >Server:LAN 192.168.1.100 > > >Forwarding Address:all > > > > > >i can connect the ftp server inside the lan, but not outside. > > >any ideas? > > > > > > > > > > > >____________________________________________________ > > >Want to buy your Pack or Services from MandrakeSoft? > > >Go to http://www.mandrakestore.com > > >Join the Club : http://www.mandrakeclub.com > > >____________________________________________________
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________