Linux IPTables Mangling Rule

Posted on 2011-04-19
Medium Priority
Last Modified: 2012-05-11
I'm looking for a way to create an iptables mangling rule that will allow traffic from a local ip and port to be redirected to an external ip address. I realize this is normally not a good idea, but a proprietary piece of software we are using requires connections to be made from non-internal IP addresses on the LAN.
Question by:nlhess2003
  • 2

Expert Comment

ID: 35427545
like this?
iptables -t mangle -A FORWARD -i eth1 -o eth0 -p tcp -m multiport --dports 1024:5189,5191:8079,8081:65535 -j MARK --set-mark 100

Expert Comment

ID: 35427555
or this:
iptables -t mangle -A FORWARD -i eth1 -o eth0 -s -d -p tcp -m multiport --dports 1024:5189,5191:8079,8081:65535 -j MARK --set-mark 100

Accepted Solution

undersky earned 2000 total points
ID: 35427716
so you just look for port forwarding?

 to allow traffic from local ip you need:

sudo iptables -I INPUT -s local.ip(s)/mask(if need) -j ACCEPT

for redirect to external port:

sudo iptables -t nat -A PREROUTING -i eth*(here interface number) -p tcp --dport (localport) -j DNAT --to-destination external.ip:externalport.

sudo iptables -I FORWARD -s (local ip's that allow to redirect) -j ACCEPT

second way, if you have access to both computers, you can redirect port via SSH:

ssh -L localport:external.ip:externalip.port *user*@external.ip


ssh -L 3309:localhost:3309 admin@

this will connect mysql localhost port, from, to my 3309 port

Featured Post

Granular recovery for Microsoft Exchange

With Veeam Explorer for Microsoft Exchange you can choose the Exchange Servers and restore points you’re interested in, and Veeam Explorer will present the contents of those mailbox stores for browsing, searching and exporting.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
Introduction We as admins face situation where we need to redirect websites to another. This may be required as a part of an upgrade keeping the old URL but website should be served from new URL. This document would brief you on different ways ca…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
Suggested Courses
Course of the Month13 days, 9 hours left to enroll

750 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question