Re: iptables: can't set any ip address in rules

"Salim" <[email protected]>
Newsgroups gmane.network.nocat
Message-ID <00d001c5b1eb$39301310$205f030a@askeyrd3>
 again typo, sorry i cant cut and paste... the command was


>iptables -t filter -A INPUT -d 192.168.1.1 -j DROP

with result
> Chain INPUT (Policy ACCEPT)
> target           DROP
> prot             all
> opt               --
> source          anywhere
> destination    0.0.0.0

----- Original Message -----
From: "Salim" <[email protected]>
To: "ulrich schwarz" <[email protected]>
Cc: <[email protected]>
Sent: Monday, September 05, 2005 3:19 PM
Subject: Re: [NoCat] iptables: can't set any ip address in rules


> Hello Ulrich,
>     thanks for the reply.
> actually that was a typo, I did include -t nat in my actual command. I
> corrected my post just now.
>
> I issued the command you gave, the result is same.
>
> >iptables -t filter -A INPUT 192.168.1.1 -j DROP
>
> and then
> >iptables -L
>
> it showed as
>
> Chain INPUT (Policy ACCEPT)
> target           DROP
> prot             all
> opt               --
> source          anywhere
> destination    0.0.0.0
>
> nothing in  FORWARD and OUTPUT chains.
>
> regards
> Salim
>
> ----- Original Message -----
> From: "ulrich schwarz" <[email protected]>
> To: "Salim" <[email protected]>
> Cc: <[email protected]>
> Sent: Monday, September 05, 2005 3:02 PM
> Subject: Re: [NoCat] iptables: can't set any ip address in rules
>
>
> > Salim wrote:
> >
> > > Hello all,
> > >     I am not able to set any rule that contsin ip address in the
> iptables.
> > > For example I give this command
> > >
> > >
> > >>iptables -t -A PREROUTING -d 1.1.1.1 -j DNAT --to-destination 2.2.2.2
> >
> > hello salim,
> >
> > if you omit the table name after the -t parameter, AFAIK the filter
> > table is assumed as default. in other words, the above statement gets
> > interpreted as follows:
> >
> > iptables -t filter -A PREROUTING -d 1.1.1.1 -j DNAT --to-destination
> 2.2.2.2
> >
> > unfortunately, there is no prerouting chain in the filter table, this
> > chain only exists in the nat and mangle tables.
> >
> > i suppose the command you are looking for is:
> >
> > iptables -t nat -A PREROUTING -d 1.1.1.1 -j DNAT --to-destination
2.2.2.2
> >
> > i always loved this page for such issues, especially the diagram that
> > shows how packets travel through the chains and tables:
> >
> >
>
http://iptables-tutorial.frozentux.net/iptables-tutorial.html#TRAVERSINGOFTA
> BLES
> >
> > you can also try something simple like
> >
> > iptables -t filter -A INPUT -d 192.168.1.1 -j DROP
> > iptables -L
> >
> > to see if your iptables work.
> >
> > [...]
> > > I am using Redhat Linux 2.4.25
> > > iptables v1.3.3
> > > MIPS embedded system.
> > >
> > > I am confused. Any help will be greatly appreciated.
> > >
> > > regards
> > > Salim
> >
> > HTH, regards,
> >
> > ulric
>
>
> _______________________________________________
> NoCat mailing list
> [email protected]
> http://lists.nocat.net/mailman/listinfo/nocat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.