NetFilter
[Top] [All Lists]

Re: DNAT not working

To: Mail List - Netfilter <netfilter@lists.netfilter.org>
Subject: Re: DNAT not working
From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Date: Fri, 22 Dec 2006 22:14:37 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <458C4254.4060007@riverviewtech.net>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Plouf !
References: <458BF3C2.4050700@initon.com> <458C4254.4060007@riverviewtech.net>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Mozilla Thunderbird 1.0.6 (Windows/20050716)
Hello,

Grant Taylor a écrit :
Balazs Fulop wrote:

If I telnet 192.168.3.1 25 on the firewall, an SMTP session starts. If I telnet from outside (coming on eth0), it waits until timeout.

I am not surprised that telnet to a private address from the outside fails. ;-)

It does not look like you are SNATing / MASQUERADing your traffic back out to the internet.

You do not need to SNAT/MASQUERADE return traffic. The NAT code does it implicitly. However, the target host must have a (default) route back to the outside via the NATing gateway.


<Prev in Thread] Current Thread [Next in Thread>