Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #174683

Re: iptables question

From Igor Cicimov <icicimov@gmail.com>
Newsgroups linux.debian.user
Subject Re: iptables question
Date 2016-11-14 03:10 +0100
Message-ID <sDeSD-o3-45@gated-at.bofh.it> (permalink)
References <sCNSp-7BL-15@gated-at.bofh.it> <sCP7P-8pY-13@gated-at.bofh.it> <sCQQn-18E-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 13 Nov 2016 11:20 am, "deloptes" <deloptes@gmail.com> wrote:
>
> Joe wrote:
>
> > On Sat, 12 Nov 2016 22:15:45 +0100
> > deloptes <deloptes@gmail.com> wrote:
> >
> >> Hi,
> >> I need some help and I'll appreciate it.
> >>
> >> I have a firewall with iptables behind the modem.
> >> on this firewall I have
> >>         eth0 with ip 10..1 to the modem ip: 10..12
> >>         eth1 with ip 192..1 to the intranet
> >>
> >> iptables is doing SNAT from 192..1 to 10..1
> >>
> >> I wonder how I can ssh from 192..NN to 10..NN
> >> What magic should I apply to make it happen?
> >>
> >> Thanks in advance
> >>
> >>
> >
> > Can we take it that this does not work now? If that is the case, are
> > you sure that iptables is preventing it? There are other possible
> > reasons for a new ssh link not to work.
> >
>
> Yes, it is not working and yes it might be a different issue. So here is
> some additional information, if you wish.
>
> >From one computer ip 10..6 I can ssh to 10..7 and vv.
> I also see that iptables forwards to the output, but in the output nothing
> happens. So it is either in the output chain, or the back route blocks.
>
> > A typical simple iptables script will allow what you want to do to
> > happen already, so there must either be some iptables restriction in
> > place now, or there is some other reason for ssh not working. Are you
> > able to connect to the modem web configuration page from the 192.
> > network?
> >
>
> Yes I forgot to mention that I can connect from 192..NN to the modem ip
via
> ssh lets say 10..200.
>
> On the modem there is also firewall. I tried disableing it but it did not
> help.
>
> And you can bet there is restriction - basically it is pretty tight and is
> opened only what is needed to intranet and basically all to modem net
>
> > The SNAT should not be an issue, it can handle all protocols
> > transparently, and ssh uses the same tcp protocol as http.
> >
> > If there are iptables restrictions on outgoing protocols, you need to
> > find the rule permitting tcp/80 to be forwarded, copy it and replace 80
> > with 22. Once this is working, we can restrict the destination to the
> > 10. network, as presumably any existing port 80 rule allows connection
> > to anywhere and you may not want that for ssh.
>
> there is nothing regarding the output - no rules based on ports
>
> thanks
>

Run tcpdump and check whats happening

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

iptables question deloptes <deloptes@gmail.com> - 2016-11-12 22:20 +0100
  Re: iptables question Joe <joe@jretrading.com> - 2016-11-12 23:40 +0100
    Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 01:30 +0100
      Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:50 +0100
      Re: iptables question Michael Milliman <michael.e.milliman@gmail.com> - 2016-11-13 12:40 +0100
        Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 16:10 +0100
          Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 18:00 +0100
            Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 20:50 +0100
              Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 21:20 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 21:50 +0100
                Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-13 22:50 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
                Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-14 00:30 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 00:50 +0100
                Re: iptables question Henning Follmann <hfollmann@itcfollmann.com> - 2016-11-14 13:10 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 20:20 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 01:00 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-14 23:10 +0100
      Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:10 +0100
        Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 08:20 +0100
          Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 09:10 +0100
    Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:40 +0100
      Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 11:10 +0100
        Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 11:40 +0100
          Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 13:40 +0100
            Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 15:00 +0100
              Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:00 +0100

csiph-web