/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Ronneil Camara <[EMAIL PROTECTED]> wrote: > > Hi. I'm sorry if I emailed you. I saw your post regarding port > forwarding. I normally recommend that people E-mail the mailing list instead of sending to me directly. I don't always get to my mail in a timely fashion, though I suppose it might seem that I do, sometimes. However, it is more efficient to ask a group of people, because it's more likely that someone else in the group will be able to provide you an answer. If you E-mail me directly, you might have to wait, and further, I might not have the answer you want, which wastes both our time. > How will I execute ipchains so that anyone from the internet when he > points to my linux box at port 110(pop3) will be redirected to an > internal pop3 server at port 110? The reason you are having trouble doing this with ipchains, is that ipchains is the wrong tool. You need the "ipmasqadm" tool: http://juanjox.kernelnotes.org/#ipmasqadm > Assuming that I have an ip address for my ppp as 200.200.200.1 and my > internal pop3 server ip address is 192.168.1.1. > > I have tried the commands below but it doesn't work. > > ipchains -A input -p tcp -s 200.200.200.1/32 -d 192.168.1.1/32 -j REDIRECT 110 > ipchains -A input -p udp -s 200.200.200.1/32 -d 192.168.1.1/32 -j REDIRECT 110 Ipchains is merely a tool to decide if packets are allowed or not. The above rule says, "If a packet comes in, and its source address is 200.200.200.1, and its destination is 192.168.1.1, and the protocol is TCP, then redirect it to port 110 on the this machine." You see, it doesn't cause the packet to be sent to another machine. The packet would have to be coming FROM THIS MACHINE, and going TO THE POP SERVER. You would somehow have to get your POP program to send such a packet to your firewall, and that's a very unlikely case. Even if you did succeed, the traffic is being sent to the firewall's POP3 port, not the server you intended. What you need is the ipmasqadm tool, which gives you the "portfw" module to accomplish what you want: ipmasqadm portfw -a -P tcp -L 200.200.200.1 110 -R 192.168.1.1 110 This causes incoming TCP traffic destined for 200.200.200.1, port 110, to be forwarded to the machine at 192.168.1.1, port 110. -- [EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience. sometimes known as David DeSimone || Experience comes from bad judgment." http://www.dallas.net/~fox/ || -- Life Lessons _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
