2 internet connection problem

Posted on 2005-04-26
Last Modified: 2010-03-18
---------| external ip eth0 | ----------
         --------------------------           |         |---------------------------
                                              |  -------| Internal IP eth1    |
         --------------------------           |         |--------------------------  
---------| external Ip eth2 | ----------

i want to put web and ftp traffic to eth2 and all other traffic to eth0
is it possible can anybody help me to do that

here is my config
iptables -t nat -A POSTROUTING -o eth2 -s -d ! -p tcp --dport 80 -j SNAT --Extermal IP on Eth2
iptables -t nat -A POSTROUTING -o eth0 -s -d ! -j  SNAT --External IP on Eth0       U     0      0        0 eth0      U     0      0        0 ipsec0   UG    0      0        0 ipsec0       U     0      0        0 eth2   UG    0      0        0 ipsec0        U     0      0        0 eth1   UG    0      0        0 ipsec0              U     0      0        0 lo             UG    1      0        0 eth0              UG    2      0        0 eth2

Thanks is Advance
Question by:snedelchev
    LVL 9

    Accepted Solution

    Hi :-)

    This requires the use of iproute2. iproute2 itself does not "know" how to forward by port, but if you mark the packet, then you may use the "fwmark" classifier. Add this to your configuration:

    iptables -t mangle -I INPUT -p tcp  --destination-port 80 -j MARK --set-mark 68482
    iptables -t mangle -I FORWARD -p tcp --destination-port 80 -j MARK --set-mark 68482

    /sbin/ip route add dev eth1 table natips
    /sbin/ip route add dev lo  scope link table natips
    /sbin/ip route add default via dev eth2 table natips
    /sbin/ip route flush cache

    /sbin/ip rule add fwmark 68482 table natips

    The number I used is just an arbitary number. You can change it if you like.
    Also edit "/etc/iproute2/rt_tables" and add a line there that says:
    200     natips

    LVL 3

    Author Comment

    Thank you e-tsik
    i put this
    iptables -A PREROUTING -i eth1 -t mangle -p tcp --dport 80 -j MARK --set-mark 66
    to working now i'm testing
    i think it working thank you very mutch
    i will reward soon as i finish testing.
    LVL 9

    Expert Comment


    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
    Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
    how to add IIS SMTP to handle application/Scanner relays into office 365.
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now