Linux Sendmail Outgoing mail problem

Hi all experts :o)

I have a setup that is the following:
Linux in Bridge mode with sendmail and snort


Eth0+eth1=no ipaddress
eth2= and is running sendmail
local mailserver is

So when i receive email from internet my router points the mail to port 25 of the eth2 it is being scanned by clam and sendmail is configured to forward to local mail server on

The problem is how do i do it from local lan and out?
I need some way to force all port 25 traffic to eth2 ?
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

you can use iptables DNAT to redirect the traffic

Have a look at this previous qustion
benjshAuthor Commented:
Ok I tried
Rotuer----Eth0(no ip)---Snortinline box-eth1(no ip)---LocalLan-Mailserver
eth2 has and the mail server has
running in bridge mode:

ifconfig eth0 down
ifconfig eth1 down
brctl addbr br0
brctl stp br0 off
brctl addif br0 eth0
brctl addif br0 eth1
ifconfig br0 up
ifconfig eth0 up
ifconfig eth1 up
ifconfig eth2 netmask up
modprobe ip_queue
iptables -t nat -A PREROUTING -i br0 -p tcp --dport 25 -j DNAT --to-destination
iptables -A FORWARD -j QUEUE

this seems to work for local users when they telnet 25 they get the local mail server but people from the internet that telnet 25 simple dont get any connection at all.

Do you see the setup?
Im not so sure becuase Im not an expert on network bridging you could try and replace the -i br0 with two iptables lines for each real interface eth0 eth1
benjshAuthor Commented:
I tried to replace it and the problem is that:
when i put eth2 in the local lan
it works from inside and out but not internet and in
and if i put eth2 in the dsl router it works from internet and in but not from local lan and out

So is there a way so the same cable can see both internal and external network places so it would work?
Hi :-)

The target you should use is REDIRECT rather than DNAT

/sbin/iptables -t nat -I PREROUTING -i br0 -s -p tcp --dport 25 -j REDIRECT --to-port 25

Or maybe

/sbin/iptables -t nat -I PREROUTING -i eth0 -s -p tcp --dport 25 -j REDIRECT --to-port 25

In order to issue something like -i eth0, you need ebtables (see EBTables, is included on the mainstream 2.6 kernel but needed to be patched to a 2.4 kernel.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Linux Networking

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.