troubleshooting Question

using DNAT and IPtables not working for second of two public interfaces

Avatar of bradber
bradber asked on
Unix OSSoftware FirewallsOS Security
4 Comments1 Solution564 ViewsLast Modified:
Greetings,
I am an ubuntu noob and would appreciate help with DNAT on Ubuntu 12.04, which I am using for a firewall/router.  I have two public interfaces and one private interface. I want to DNAT traffic from public interface eth0 to 10.1.1.5 on the private LAN, and I want to DNAT traffic from public interface eth2 to 10.1.1.6 on the private LAN.

I am using IPTABLES, and this is my configuration:



/sbin/iptables -t nat -A PREROUTING -p tcp -d X.X.X.X --dport 80 -j DNAT --to
10.1.1.5:80

/sbin/iptables -t nat -A PREROUTING -p tcp -d y.y.y.y --dport 80 -j DNAT --to
10.1.1.6:80


where:
x.x.x.x = eth0
y.y.y.y = eth2

DNAT works for eth0 but not for eth2, although I can ping y.y.y.y from the public side.  
 
Can anyone please help me determine why DNAT is not working for eth2? Does DNAT only work on the primary interface?

Thanks in advance!
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 4 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 4 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros