iptables question

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
here is what I need: I have a linux iptables machine, forwarding ports to machines inside the nat for VPN. The machines do not have a default gateway (we are testing wan application stuff, and don't want to change it trying to go to the web via this connection) on this interface.

Can I do something like this (mangle tables maybe?)

1. World client, 10.0.0.1
2. Iptables NAT box, 20.0.0.1 (Live) 30.0.0.1
3. Internal VNC server 30.0.0.2

I want the connection from 10.0.0.1 to hit the 20.0.0.1 IP, get changed so source appears to be from 30.0.0.1 to 30.0.0.2 and have it route from 30.0.0.2 back out to 10.0.0.1?


Hope this makes sense.
 

Devistater

Diamond Member
Sep 9, 2001
3,180
0
0
You might want to try:
http://www.fwbuilder.org/
I dont know much about IPtables, but I do like the looks of that tool. It builds IPtables to your specs with a GUI. I came across it in referance to the linksys wrt54g, they had an option to do specific builds for that router. But it is normally used to setup IPtables for linux stuff. They also came out with a version that runs on windows recently too.
 

Devistater

Diamond Member
Sep 9, 2001
3,180
0
0
Originally posted by: nweaver
I don't have a gui on that machine

What the fwbuilder program does is make up an iptables for you. So you can make it up on any machine and copy the appropriate files over to the machine in question.

As for if you can do that specific thing in question without requireing something outside of iptables, I'm not sure. My network knowledge isn't up to that question
 

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
I think I might have some iptables stuff working. I did have to add the gatway, but I just don't allow access to anything but the 5900-5920 ports out or into the machine, so it can't use those ports for anything else.

I was looking for a VNC proxy (great idea!) but could only find an alpha version, and I need to have this fairly stable, or else the test execution team from India will be getting me out of bed alot
 

Corey0808

Senior member
Sep 26, 2003
463
0
0
Why don't you try and go here and check out the networking forum. It is definitely more linux oriented.

LQ

From a high level standpoint it seems you have a routing / masquarading task here. I think there are commands to change the source if you check out:

IPTables Tutorial

This command might be the one for you, not sure though:

DNAT

Good Luck!
 

Brazen

Diamond Member
Jul 14, 2000
4,259
0
0
It almost sounds like maybe you want to use masquerading on the traffice coming IN to the network.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |