[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Iptables output redirect quest

Posted on 2009-02-24
2
Medium Priority
?
1,516 Views
Last Modified: 2012-05-06
I have an application that sends output out on a sample port which must be redirected at the server level back to a second port in order for the application to process the information correctly.

For example, we will use:
IP:  172.80.4.155
Redirect from: 443
Redirect to: 8443
2nd IP:  172.80.4.156

I have the following rule which works fine running by itself, but I need to introduce a second IP into the system and each IP needs to redirect their output back to themselves on the new port.

/sbin/iptables -t nat -A OUTPUT -j REDIRECT -p tcp -d 172.80.4.155/32 --dport 443 --to-ports 8443

/sbin/iptables -t nat -A OUTPUT -j REDIRECT -p tcp -d 172.80.4.156/32 --dport 443 --to-ports 8443

Does anyone know how I could accomplish this?  Using PREROUTING will not work as it isn't redirecting the output like the rule above does.  
0
Comment
Question by:xiaoyunwu
2 Comments
 
LVL 27

Accepted Solution

by:
Nopius earned 2000 total points
ID: 23728797
> each IP needs to redirect their output back to themselves on the new port.

according to manual page
'It redirects the packet to the machine itself by changing the  destination IP  to  the  primary  address  of  the  incoming  interface'

so that in modified IP packet, the source IP address will always be 172.80.4.155 regardless of original source IP.
Try to use DNAT instead:
/sbin/iptables -t nat -A OUTPUT  -p tcp -d 172.80.4.155/32 --dport 443 -j REDIRECT --to-destination :8443
/sbin/iptables -t nat -A OUTPUT  -p tcp -d 172.80.4.156/32 --dport 443 -j REDIRECT --to-destination :8443

P.S. '-to-destination :8443' is not misspelled (without IP), use it as is :-)
0
 

Author Comment

by:xiaoyunwu
ID: 23733454
What version of iptables are you using?  I'm using 1.3.5 and it doesn't support the --to-destination flag.  This is for a Java based application run under Tomcat that posts information back to itself which is why I need to redirect the output to port 8443.  I am already NAT'ing:
/sbin/iptables -t nat -A PREROUTING -p tcp -d 172.80.4.155 --dport 443 -j DNAT --to 172.80.4.155:8443
/sbin/iptables -t nat -A PREROUTING -p tcp -d 172.80.4.156 --dport 443 -j DNAT --to 172.80.4.156:8443

But this won't handle redirecting the output back to itself. I need to find a way to redirect the output in a similar manner to the rules above.

/sbin/iptables -t nat -A OUTPUT  -p tcp -d 172.80.4.155/32 --dport 443 -j REDIRECT --to-destination :8443
iptables v1.3.5: Unknown arg `--to-destination'
Try `iptables -h' or 'iptables --help' for more information.


Do you have any other ideas?
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question