IPTable Rules... again

nullv at gmx.com nullv at gmx.com
Thu Mar 8 15:16:48 UTC 2012


Hi,

I have the following  rules on my router/gateway: 

*nat
:PREROUTING ACCEPT 
:INPUT ACCEPT 
:OUTPUT ACCEPT 
:POSTROUTING ACCEPT 
-A POSTROUTING -d 93.186.25.52/32 -m comment --comment "bb" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p tcp -m tcp --dport 53 -m comment --comment "domain" o eth0 -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p udp -m udp --dport 53 -m comment --comment "domain" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p tcp -m tcp --dport 995 -m comment --comment "pop3s" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p udp -m udp --dport 995 -m comment --comment "pop3s" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p tcp -m tcp --dport 587 -m comment --comment "submission" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.0/8 -p udp -m udp --dport 587 -m comment --comment "submission" -j SNAT --to-source 41.94.39.49-41.94.39.51
-A POSTROUTING -s 10.0.0.3/32 -j o eth0 -j SNAT --to-source 41.94.39.49-41.94.39.51
COMMIT
*filter
:INPUT ACCEPT 
:FORWARD ACCEPT 
:OUTPUT ACCEPT 
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p icmp -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 53 -m comment --comment "domain" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p udp -m udp --dport 53 -m comment --comment "domain" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 995 -m comment --comment "pop3s" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p udp -m udp --dport 995 -m comment --comment "pop3s" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 587 -m comment --comment "submission" -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p udp -m udp --dport 587 -m comment --comment "submission" -j ACCEPT
-A FORWARD -s 10.0.0.3/32 -i eth1 -o eth0 -j ACCEPT
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT

for some reason I can't make a connection to the external mail server from inside the lan. even from the 10.0.0.3 address which should be allowed to do anything.
everything used to work when i used MASQUERADing but stopped once i switched to SNAT. 
Can anybody help me? What am I doing wrong??

Thanks


More information about the users mailing list