Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] iptables and port-forwarding concerns



Quoth David Santinoli (Thu 2004-04-22 12:51:09AM +0200):

> On Thu, Apr 22, 2004 at 12:19:00AM +0200, Godwin Stewart wrote:
>
> > 4) Given that I have a static public IP address, is IP masquerading
> > the right solution for distributing the Internet connection to the LAN
> > or should I be looking at full NAT instead in the first place?
> 
> I'm not sure I got this right: are you just wondering whether you can
> substitute "-j SNAT" for "-j MASQUERADE", or is there more?

Nope, SNAT works like this:

iptables -A POSTROUTING -o eth0 -j SNAT --to-source <your firewall's IP>

-- 
Josh Glover

GPG keyID 0xDE8A3103 (C3E4 FA9E 1E07 BBDB 6D8B  07AB 2BF1 67A1 DE8A 3103)
gpg --keyserver pgp.mit.edu --recv-keys DE8A3103

Attachment: pgp00054.pgp
Description: PGP signature


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links