Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


IPCop forward external to external red

Posted on 2011-09-28
Medium Priority
Last Modified: 2012-05-12
Hi Experts,

What we are trying to do is route or forward traffic that comes to our external ip (x.x.x.x) to another external ip (y.y.y.y).

We know how to forward from external to internal but we are looking to go red to red.

Any Ideas

Question by:nikdonovanau
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 10

Expert Comment

ID: 36813795
With the default settings of IPCop, this is not possible, because IPCop is cutting traffic from red to red..

Possible workarounds:

1. let the modem/router do that, upstream, or
2. add an iptable rule in your /etc/rc.d/rc.firewall.local file allowing traffic from x.x.x.x to y.y.y.y, or
3. forward the traffic to some host inside your LAN or DMZ that is going to re-forward that traffic to y.y.y.y

Good luck.
LVL 10

Accepted Solution

pfrancois earned 2000 total points
ID: 36814032
I advice you workaround #2. You will have to add the rules after the line containing "start)".

Author Closing Comment

ID: 36818509
Thanks for the advise. Much appreciated.
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.


Author Comment

ID: 36901437
For anyone out there trying to do this.  This is how I achieved it.

After start) in /etc/rc.d/rc.firewall.local

/sbin/iptables -t nat -A CUSTOMPREROUTING -p tcp -i wan-1 --dport [port] -j DNAT --to-destination [dest_ip]:[dest_port]

/sbin/iptables -A CUSTOMFORWARD -p tcp -i wan-1 -d [dest_ip] --dport [dest_port] -j ACCEPT

Thanks a lot.
LVL 10

Expert Comment

ID: 36902004
Thank you for this very useful complement of information. Instead of option "-i wan-1", I would say "-i $RED_DEV", right?

Author Comment

ID: 36908063
Sure I think you can use the variables from the config file.

My config file seemed to have $RED_DEV_1 or somthing like that so I chose to just hard code the name of my wan ethernet interface.

Featured Post

Learn by Doing. Anytime. Anywhere.

Do you like to learn by doing?
Our labs and exercises give you the chance to do just that: Learn by performing actions on real environments.

Hands-on, scenario-based labs give you experience on real environments provided by us so you don't have to worry about breaking anything.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…

660 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question