Difference between revisions of "IPtable Forward Port"
From MS Computech
Line 1: | Line 1: | ||
===== This is sample rule to forward rdp to host. LinixGateway-->>Windows Server2003 ===== | ===== This is sample rule to forward rdp to host. LinixGateway-->>Windows Server2003 ===== | ||
− | + | Forward rule Listen port 3000 forward to 3389 | |
<pre>echo 1 > /proc/sys/net/ipv4/ip_forward</pre> | <pre>echo 1 > /proc/sys/net/ipv4/ip_forward</pre> | ||
− | |||
Forward to 2003 RDP And Nat<br> | Forward to 2003 RDP And Nat<br> | ||
<pre>sbin/iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 3000 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT<br>/sbin/iptables -A PREROUTING -t nat -p tcp -i eth0 --dport 3000 -j DNAT --to-destination 172.31.255.2:3389</pre> | <pre>sbin/iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 3000 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT<br>/sbin/iptables -A PREROUTING -t nat -p tcp -i eth0 --dport 3000 -j DNAT --to-destination 172.31.255.2:3389</pre> | ||
− | <br> | + | <br>WWW Fileshare<br> |
− | WWW Fileshare<br> | ||
<pre>/sbin/iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 8000 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT<br>/sbin/iptables -A PREROUTING -t nat -p tcp -i eth0 --dport 8000 -j DNAT --to-destination 172.31.255.2:8000</pre> | <pre>/sbin/iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 8000 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT<br>/sbin/iptables -A PREROUTING -t nat -p tcp -i eth0 --dport 8000 -j DNAT --to-destination 172.31.255.2:8000</pre> | ||
<br> | <br> | ||
<pre>/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE<br></pre> | <pre>/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE<br></pre> |
Revision as of 17:05, 1 December 2008
This is sample rule to forward rdp to host. LinixGateway-->>Windows Server2003
Forward rule Listen port 3000 forward to 3389
echo 1 > /proc/sys/net/ipv4/ip_forward
Forward to 2003 RDP And Nat
sbin/iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 3000 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT<br>/sbin/iptables -A PREROUTING -t nat -p tcp -i eth0 --dport 3000 -j DNAT --to-destination 172.31.255.2:3389
WWW Fileshare
/sbin/iptables -A FORWARD -i eth0 -o eth1 -p tcp --dport 8000 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT<br>/sbin/iptables -A PREROUTING -t nat -p tcp -i eth0 --dport 8000 -j DNAT --to-destination 172.31.255.2:8000
/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE<br>