Solved

IPCop forward external to external red

Posted on 2011-09-28
6
416 Views
Last Modified: 2012-05-12
Hi Experts,

What we are trying to do is route or forward traffic that comes to our external ip (x.x.x.x) to another external ip (y.y.y.y).

We know how to forward from external to internal but we are looking to go red to red.

Any Ideas

Cheers
Nik
0
Comment
Question by:nikdonovanau
  • 3
  • 3
6 Comments
 
LVL 10

Expert Comment

by:pfrancois
ID: 36813795
With the default settings of IPCop, this is not possible, because IPCop is cutting traffic from red to red..

Possible workarounds:

1. let the modem/router do that, upstream, or
2. add an iptable rule in your /etc/rc.d/rc.firewall.local file allowing traffic from x.x.x.x to y.y.y.y, or
3. forward the traffic to some host inside your LAN or DMZ that is going to re-forward that traffic to y.y.y.y

Good luck.
0
 
LVL 10

Accepted Solution

by:
pfrancois earned 500 total points
ID: 36814032
I advice you workaround #2. You will have to add the rules after the line containing "start)".
0
 
LVL 1

Author Closing Comment

by:nikdonovanau
ID: 36818509
Thanks for the advise. Much appreciated.
0
Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

 
LVL 1

Author Comment

by:nikdonovanau
ID: 36901437
For anyone out there trying to do this.  This is how I achieved it.

After start) in /etc/rc.d/rc.firewall.local

/sbin/iptables -t nat -A CUSTOMPREROUTING -p tcp -i wan-1 --dport [port] -j DNAT --to-destination [dest_ip]:[dest_port]

/sbin/iptables -A CUSTOMFORWARD -p tcp -i wan-1 -d [dest_ip] --dport [dest_port] -j ACCEPT

Thanks a lot.
0
 
LVL 10

Expert Comment

by:pfrancois
ID: 36902004
Thank you for this very useful complement of information. Instead of option "-i wan-1", I would say "-i $RED_DEV", right?
0
 
LVL 1

Author Comment

by:nikdonovanau
ID: 36908063
Sure I think you can use the variables from the config file.

My config file seemed to have $RED_DEV_1 or somthing like that so I chose to just hard code the name of my wan ethernet interface.
0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question