Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #380
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Newsgroups | comp.os.linux.networking |
| Subject | Re: iptables DNAT/SNAT/ICMP done right? |
| Date | 2011-06-21 23:42 +0200 |
| Organization | Plouf ! |
| Message-ID | <itr384$2hu0$1@saria.nerim.net> (permalink) |
| References | <itq01e$2bn$1@news.m-online.net> |
Hello, Christian Brandt a écrit : > > I am uncertain about my implementations of DNAT, SNAT and the importance > of ICMP - though I think ICMP is a good thing to have around in case of > congestion&family. You don't describe your requirements, so it is not possible to tell if your ruleset is adequate. > # INPUT table > iptables -A INPUT -j ACCEPT -m state --state ESTABLISHED,RELATED > iptables -A INPUT -j ACCEPT -i lo > iptables -A INPUT -j ACCEPT -p icmp # ICMP Required ICMP types (error types) are already in the RELATED state. No need for a specific rule. Other ICMP types such as echo aka ping are optional. > iptables -A INPUT -j ACCEPT -i $EXT_DEV -p tcp --dport 22 # SSH If you DNAT and FORWARD all incoming SSH connections to another host, then this rule will never match. The INPUT chain sees only packets which are to be delivered to the local host. > # OUTPUT table > iptables -A OUTPUT -j ACCEPT -m state --state ESTABLISHED,RELATED > iptables -A OUTPUT -j ACCEPT -o lo > iptables -A OUTPUT -j ACCEPT -o $INT_DEV -p icmp # ICMP > iptables -A OUTPUT -j ACCEPT -o $INT_DEV -p tcp --dport 22 # SSH > iptables -A OUTPUT -j ACCEPT -o $EXT_DEV -p icmp # ICMP > iptables -A OUTPUT -j ACCEPT -o $EXT_DEV -p tcp -d $MIRROR --dport 80 # HTTP > > # FORWARD table outgoing > iptables -A FORWARD -j ACCEPT -m state --state ESTABLISHED,RELATED > iptables -A FORWARD -j ACCEPT -p icmp # ICMP > iptables -A FORWARD -j ACCEPT -o $EXT_DEV -p tcp --dport 22 # SSH > > # PREROUTING table incoming > iptables -A PREROUTING -j DNAT -i $EXT_DEV -p tcp -d $EXT_IP --dport 22 -t nat --to $INT_SYS:22 > iptables -A FORWARD -j ACCEPT -i $EXT_DEV -p tcp -d $EXT_IP --dport 22 You need -d $INT_SYS (the final destination) here. > iptables -A PREROUTING -j DNAT -i $EXT_DEV -p icmp -d $EXT_IP -t nat --to $INT_SYS > iptables -A FORWARD -j ACCEPT -i $EXT_DEV -p icmp -d $EXT_IP Same remark as above. Besides, these two rules are not needed for ICMP packets in the RELATED state. NAT automatically takes care of them. > # POSTROUTING table outgoing > iptables -A POSTROUTING -j SNAT -s $INT_SYS --to-source $EXT_IP -t nat > > # Abschluß > iptables -A INPUT -j LOG -m state --state NEW -m limit --limit $LOGLIMIT --log-prefix="netfilter-input-reject " > iptables -A INPUT -j REJECT > iptables -A OUTPUT -j LOG -m state --state NEW -m limit --limit $LOGLIMIT --log-prefix="netfilter-output-reject " > iptables -A OUTPUT -j REJECT > iptables -A FORWARD -j LOG -m state --state NEW -m limit --limit $LOGLIMIT --log-prefix="netfilter-forward-reject " > iptables -A FORWARD -j REJECT > > echo 1 >/proc/sys/net/ipv4/ip_forward
Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
iptables DNAT/SNAT/ICMP done right? Christian Brandt <brandtc@psi5.com> - 2011-06-21 13:41 +0200
Re: iptables DNAT/SNAT/ICMP done right? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-21 23:42 +0200
Re: iptables DNAT/SNAT/ICMP done right? Christian Brandt <brandtc@psi5.com> - 2011-06-24 10:39 +0200
Re: iptables DNAT/SNAT/ICMP done right? buck <buck@private.mil> - 2011-06-24 17:45 +0000
csiph-web