Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #380

Re: iptables DNAT/SNAT/ICMP done right?

From Pascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Newsgroups comp.os.linux.networking
Subject Re: iptables DNAT/SNAT/ICMP done right?
Date 2011-06-21 23:42 +0200
Organization Plouf !
Message-ID <itr384$2hu0$1@saria.nerim.net> (permalink)
References <itq01e$2bn$1@news.m-online.net>

Show all headers | View raw


Hello,

Christian Brandt a écrit :
> 
> I am uncertain about my implementations of DNAT, SNAT and the importance
> of ICMP - though I think ICMP is a good thing to have around in case of
> congestion&family.

You don't describe your requirements, so it is not possible to tell if
your ruleset is adequate.

> # INPUT table
> iptables -A INPUT       -j ACCEPT -m state --state ESTABLISHED,RELATED
> iptables -A INPUT       -j ACCEPT -i lo
> iptables -A INPUT       -j ACCEPT             -p icmp             # ICMP

Required ICMP types (error types) are already in the RELATED state. No
need for a specific rule. Other ICMP types such as echo aka ping are
optional.

> iptables -A INPUT       -j ACCEPT -i $EXT_DEV -p tcp --dport 22   # SSH

If you DNAT and FORWARD all incoming SSH connections to another host,
then this rule will never match. The INPUT chain sees only packets which
are to be delivered to the local host.

> # OUTPUT table
> iptables -A OUTPUT      -j ACCEPT -m state --state ESTABLISHED,RELATED
> iptables -A OUTPUT      -j ACCEPT -o lo
> iptables -A OUTPUT      -j ACCEPT -o $INT_DEV -p icmp             # ICMP
> iptables -A OUTPUT      -j ACCEPT -o $INT_DEV -p tcp --dport 22   # SSH
> iptables -A OUTPUT      -j ACCEPT -o $EXT_DEV -p icmp             # ICMP
> iptables -A OUTPUT      -j ACCEPT -o $EXT_DEV -p tcp -d $MIRROR --dport 80   # HTTP
> 
> # FORWARD table outgoing
> iptables -A FORWARD     -j ACCEPT -m state --state ESTABLISHED,RELATED
> iptables -A FORWARD     -j ACCEPT             -p icmp             # ICMP
> iptables -A FORWARD     -j ACCEPT -o $EXT_DEV -p tcp --dport 22   # SSH
> 
> # PREROUTING table incoming
> iptables -A PREROUTING  -j DNAT   -i $EXT_DEV -p tcp  -d $EXT_IP --dport 22  -t nat --to $INT_SYS:22
> iptables -A FORWARD     -j ACCEPT -i $EXT_DEV -p tcp  -d $EXT_IP --dport 22

You need -d $INT_SYS (the final destination) here.

> iptables -A PREROUTING  -j DNAT   -i $EXT_DEV -p icmp -d $EXT_IP -t nat --to $INT_SYS
> iptables -A FORWARD     -j ACCEPT -i $EXT_DEV -p icmp -d $EXT_IP

Same remark as above. Besides, these two rules are not needed for ICMP
packets in the RELATED state. NAT automatically takes care of them.

> # POSTROUTING table outgoing
> iptables -A POSTROUTING -j SNAT -s $INT_SYS --to-source $EXT_IP -t nat
> 
> # Abschluß
> iptables -A INPUT       -j LOG -m state --state NEW -m limit --limit $LOGLIMIT --log-prefix="netfilter-input-reject "
> iptables -A INPUT       -j REJECT
> iptables -A OUTPUT      -j LOG -m state --state NEW -m limit --limit $LOGLIMIT --log-prefix="netfilter-output-reject "
> iptables -A OUTPUT      -j REJECT
> iptables -A FORWARD     -j LOG -m state --state NEW -m limit --limit $LOGLIMIT --log-prefix="netfilter-forward-reject "
> iptables -A FORWARD     -j REJECT
> 
> echo 1 >/proc/sys/net/ipv4/ip_forward

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

iptables DNAT/SNAT/ICMP done right? Christian Brandt <brandtc@psi5.com> - 2011-06-21 13:41 +0200
  Re: iptables DNAT/SNAT/ICMP done right? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-21 23:42 +0200
    Re: iptables DNAT/SNAT/ICMP done right? Christian Brandt <brandtc@psi5.com> - 2011-06-24 10:39 +0200
  Re: iptables DNAT/SNAT/ICMP done right? buck <buck@private.mil> - 2011-06-24 17:45 +0000

csiph-web