Re: [Security Firewall] Problem with port forwarding

florin <[email protected]>
Newsgroups gmane.linux.mandrake.security.firewall
Message-ID <[email protected]>
Hi again, 

Oh, this changes everything. 

You don't need the public router because MNF can act as a router
itself. If you want to keep it, then you need to configure DNAT on the
router in the same way you did on MNF.

You need to do a double port forwarding: from the router to MNF, and
then from MNF to the ftp server.

If you cannot create DNAT rules on the router than you cannot do what
you're trying to do and get rid of the router and keep only MNF.

On MNF you simply need these two rules:

DNAT    wan     lan:192.168.1.101       tcp     ftp     -       all
DNAT    wan     lan:192.168.1.101       tcp     ftp-data     -       all


On 6/15/05, ibon M. B. <[email protected]> wrote:
> 
> internet
>   |
>   |
>   |
> (x.x.x.x- Public IP)Router(192.168.10.1 Internal IP)
>                                                  |
>                                                  |
>                                                  |
>                                         (192.168.10.254
> eth1)MNF(192.168.1.254 eth0)
> 
>        |
> 
>        |
> 
>        |
> 
>      LAN (192.168.1.0/24)
> 
> 
> 
> 
> >From: florin <[email protected]>
> >Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
> >To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
> >Subject: Re: [Security Firewall] Problem with port forwarding
> >Date: Wed, 15 Jun 2005 20:55:43 +0200
> >
> >router, what router ... simply draw us an ascii map of your situation
> >to have a better idea ...
> >
> >On 6/15/05, ibon M. B. <[email protected]> wrote:
> > > the router is using NAT, i also had tried:
> > > DNAT    wan      lan:192.168.1.101      tcp     ftp    -    public_ip
> > >
> > > and doesn´t work.
> > > i don´t know what i´m doing wrong:((
> > >
> > > >Assuming your LAN is using NAT, none of these will work because you
> >have to
> > > >specify the public IP in the forward portion of the DNAT rule.  (it has
> >to
> > > >know where to listen)
> > > >
> > > >Here is a rule that we use to gain SSH into a linux box within the lan
> >from
> > > >the wan (where xxx is your public IP)
> > > >
> > > >DNAT    wan      lan:192.168.69.3       tcp     ssh     -
> > > >xxx.xxx.xxx.xxx
> > > >
> > > >ftp and ftp-data would be the same.  Be sure and remove those other
> >rules.
> > > >Jim
> > >
> > >
> > > >From: "ibon M. B." <[email protected]>
> > > >Reply-To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
> > > >To: security-firewall-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org
> > > >Subject: [Security Firewall] Problem with port forwarding
> > > >Date: Tue, 14 Jun 2005 10:06:26 +0000
> > > >
> > > >Thanks for your help
> > > >I have created a custom rule to forward the ftp traffic to a computer
> >in my
> > > >lan, but port forwarding doesn´t seem to work.
> > > >Custom Rule:
> > > >Result --DNAT
> > > >Predefined Services--FTP
> > > >Protocol--FTP
> > > >Client:WAN
> > > >Server:LAN 192.168.1.100
> > > >Forwarding Address:all
> > > >
> > > >i can connect the ftp server inside the lan, but not outside.
> > > >any ideas?


cheers,
-- 
Florin
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.