IPTABLES - Dont loading some websites

Posted on 2012-08-20
Last Modified: 2012-08-21
Hey guys,

Could someone point me whats i`m missing to get my NAT working with some websites?
Some o f my rules on Transparent way:


Open in new window

iptables -P INPUT ACCEPT

Open in new window

iptables -t nat -A POSTROUTING -s -o ppp0 -j SNAT

Open in new window

echo 1 > /proc/sys/net/ipv4/ip_forward

Open in new window

Yahoo mail work sometimes.....
Paypal dont load (stuck on an infinite load)
Experts-exchange dont load (stuck on an infinite load)

Those are the websites i`m getting problem for now, other websites work fine...

After get the things working ok in transparent NAT, i will move to add rules focusing in security.
Thanks in advice.
Question by:Wisdown
    LVL 1

    Author Comment

    Checking my /var/log/syslog i see this message:

    send_packet: Operation nont permitted

    But, if i set to accept all, how something can get blocked without an rule to block?
    LVL 51

    Expert Comment

    are you asking for connecting a website with a browser on the mashine you have configured iptables?
    if so, iptables rules are most likely not the reason why you can access one site but not another one
    keep in mind that iptables -nomen est omen- is based on ip, ports and such while "accessing" a website is application layer
    LVL 1

    Author Comment

    I`m asking for the other workstations.
    My setup is:

    1 VMWare Runing Debian (guest host is windows) as Gateway with one interface eth0 doing SNAT on ppp0

    Other 2 desktops in the network runing windows 7, and 5 other VMware debians runing servers (Apache - Mail - Mysql - 2 DNS Servers).

    My guess is my setup is doing some loop in some websites.
    The sites start lod and never finish the load, after around 3 min i get an error saying the connection cant be made with the server (website)
    LVL 51

    Accepted Solution

    > My guess is my setup is doing some loop in some websites.
    this then has nothing todo with iptables

    I'm still confused what you want toarchive and where your problem is

    If iptables' SNAT is your problem, then it's a general routing problem and not restricted to websites, if a looping website is your problem, then iptables rules most likely do not count

    simple check: can you ping the host in question?
    LVL 1

    Author Comment

    Yeah i was able to ping the host, but sites get random no load times...

    By the way, i give up try set the debian and did an try on pfsense...
    Answering the questions of installer using from my previous setup, everything is working now...

    Dunno what the setup did, but at least i get this up finally.
    Thanks for try help anyway.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    What’s a web proxy server? A proxy server is a server that goes between clients and web servers, used in corporate to enforce corporate browsing policy and ensure security. Proxy servers are commonly used in three modes. A)    Forward proxy …
    Join Greg Farro and Ethan Banks from Packet Pushers ( and Greg Ross from Paessler ( for a discussion about smart network …
    Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    733 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now