[plug] Port forwarding with Iptables

Anthony J. Breeds-Taurima tony at cantech.net.au
Thu Oct 31 15:47:22 WST 2002


On Thu, 31 Oct 2002, Nigel Duff wrote:

> 
> Hi all,
> 
> I am trying to forward edonkey ports from my firewall to a machine on my
> internal network. I have played with different configurations but can't
> get it to work. I have the following policy under a 2.4.19 kernal.
> 
> iptables -t nat -A PREROUTING  -p tcp -s 0/0 -d 0/0 --destination-port
> 4660:4670 -j DNAT --to-destination 192.168.1.2:4660-4670


I'd guess
iptables -t nat -A PREROUTING  -p tcp -d externalIP/32 --dport 4660:4670 \
	-j DNAT --to-destination 192.168.1.2:4660-4670

Would be better.  You might be able to get away with specifying the input
device.  

You may also need the contrack modules loaded.

Yours Tony

   Jan 22-25 2003           Linux.Conf.AU            http://linux.conf.au/
		  The Australian Linux Technical Conference!



More information about the plug mailing list