Re: [Security Firewall] Problem with port forwarding
florin <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.firewall |
|---|---|
| Message-ID | <[email protected]> |
Hi again, Oh, this changes everything. You don't need the public router because MNF can act as a router itself. If you want to keep it, then you need to configure DNAT on the router in the same way you did on MNF. You need to do a double port forwarding: from the router to MNF, and then from MNF to the ftp server. If you cannot create DNAT rules on the router than you cannot do what you're trying to do and get rid of the router and keep only MNF. On MNF you simply need these two rules: DNAT wan lan:192.168.1.101 tcp ftp - all DNAT wan lan:192.168.1.101 tcp ftp-data - all On 6/15/05, ibon M. B. <[email protected]> wrote: > > internet > | > | > | > (x.x.x.x- Public IP)Router(192.168.10.1 Internal IP) > | > | > | > (192.168.10.254 > eth1)MNF(192.168.1.254 eth0) > > | > > | > > | > > LAN (192.168.1.0/24) > > > > > >From: florin <[email protected]> > >Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] > >To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] > >Subject: Re: [Security Firewall] Problem with port forwarding > >Date: Wed, 15 Jun 2005 20:55:43 +0200 > > > >router, what router ... simply draw us an ascii map of your situation > >to have a better idea ... > > > >On 6/15/05, ibon M. B. <[email protected]> wrote: > > > the router is using NAT, i also had tried: > > > DNAT wan lan:192.168.1.101 tcp ftp - public_ip > > > > > > and doesn´t work. > > > i don´t know what i´m doing wrong:(( > > > > > > >Assuming your LAN is using NAT, none of these will work because you > >have to > > > >specify the public IP in the forward portion of the DNAT rule. (it has > >to > > > >know where to listen) > > > > > > > >Here is a rule that we use to gain SSH into a linux box within the lan > >from > > > >the wan (where xxx is your public IP) > > > > > > > >DNAT wan lan:192.168.69.3 tcp ssh - > > > >xxx.xxx.xxx.xxx > > > > > > > >ftp and ftp-data would be the same. Be sure and remove those other > >rules. > > > >Jim > > > > > > > > > >From: "ibon M. B." <[email protected]> > > > >Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected] > > > >To: security-firewall-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org > > > >Subject: [Security Firewall] Problem with port forwarding > > > >Date: Tue, 14 Jun 2005 10:06:26 +0000 > > > > > > > >Thanks for your help > > > >I have created a custom rule to forward the ftp traffic to a computer > >in my > > > >lan, but port forwarding doesn´t seem to work. > > > >Custom Rule: > > > >Result --DNAT > > > >Predefined Services--FTP > > > >Protocol--FTP > > > >Client:WAN > > > >Server:LAN 192.168.1.100 > > > >Forwarding Address:all > > > > > > > >i can connect the ftp server inside the lan, but not outside. > > > >any ideas? cheers, -- Florin
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________