IPTable Rules... again
nullv at gmx.com
nullv at gmx.com
Thu Mar 8 15:16:48 UTC 2012
Hi,
I have the following rules on my router/gateway:
*nat
:PREROUTING ACCEPT
:INPUT ACCEPT
:OUTPUT ACCEPT
:POSTROUTING ACCEPT
-A POSTROUTING -d 93.186.25.52/32 -m comment --comment "bb" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p tcp -m tcp --dport 53 -m comment --comment "domain" o eth0 -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p udp -m udp --dport 53 -m comment --comment "domain" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p tcp -m tcp --dport 995 -m comment --comment "pop3s" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p udp -m udp --dport 995 -m comment --comment "pop3s" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p tcp -m tcp --dport 587 -m comment --comment "submission" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p udp -m udp --dport 587 -m comment --comment "submission" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.3/32 -j o eth0 -j SNAT --to-source 41.94.39.49-41.94.39.51
COMMIT
*filter
:INPUT ACCEPT
:FORWARD ACCEPT
:OUTPUT ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p icmp -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 53 -m comment --comment "domain" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p udp -m udp --dport 53 -m comment --comment "domain" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 995 -m comment --comment "pop3s" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p udp -m udp --dport 995 -m comment --comment "pop3s" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 587 -m comment --comment "submission" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p udp -m udp --dport 587 -m comment --comment "submission" -j ACCEPT
-A FORWARD -s 10.0.0.3/32 -i eth1 -o eth0 -j ACCEPT
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
for some reason I can't make a connection to the external mail server from inside the lan. even from the 10.0.0.3 address which should be allowed to do anything.
everything used to work when i used MASQUERADing but stopped once i switched to SNAT.
Can anybody help me? What am I doing wrong??
Thanks
More information about the users
mailing list