LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-21-2005, 12:53 PM   #1
<Ol>Origy
Member
 
Registered: Aug 2003
Location: Slovenia
Distribution: Arch, Debian, Embedded
Posts: 136

Rep: Reputation: 15
Question about iptables port forwarding


Hello.
I have a question about iptables firewall.
I would like to know some things about how iptables port forwarding is done. I have a RHL9 PC with 2 network cards - I use one for my internal network (static IP subnet) and the other one for internet access. The PC sorta works like a router and a firewall allowing the subnet PC's to access internet via it - gateway. I have configured the firewall to block all incoming connections from the internet except the related ones and later on opened some ports and ordered iptables to forward them to the IP of my computer (only my IP, no other) on the subnet for I use those ports (gaming, IM's, p2p, etc). Now the thing is that I just don't get it how this port forwarding really works. Does it forward the incoming connections of those ports to my subnet IP and my subnet IP only (as I assumed) or does it also forward them to the rest of the PC's on the subnet? For some reason I see a lot of applications work on other PC's on the subnet but I haven't really opened any ports for them. Is it possible that iptables allows those applications to use the ports I registered as my own?
Thanks in advice.
 
Old 05-21-2005, 01:53 PM   #2
comptiger5000
Member
 
Registered: May 2005
Distribution: Fedora Core Since version 3
Posts: 193

Rep: Reputation: 30
port forwarding is only reffering to inbound connections, not outbound
 
Old 05-21-2005, 04:27 PM   #3
<Ol>Origy
Member
 
Registered: Aug 2003
Location: Slovenia
Distribution: Arch, Debian, Embedded
Posts: 136

Original Poster
Rep: Reputation: 15
Quote:
Originally posted by comptiger5000
port forwarding is only reffering to inbound connections, not outbound
I know this but that's not exactly what I asked. The applications that establish a connection with a server work properly as the connection becomes "related" and the firewall passes it by. However some other applications act as servers and require connections to be made from clients outside the subnet - they have to get passed the firewall but since the firewall is configured to drop all unrelated incoming connection requests, those apps should not work properly. What I am asking is if those applications (on another subnet PC) can work using a common port I originally programmed to be forwarded to my IP. For example I let iptables know that port 6666 tcp should be forwarded to my IP let's say 192.168.0.3. If this is the case, does iptables also allow an application on PC2 whose IP is 192.168.0.2 to use this port 6666 tcp to accept incoming connections from the internet?
 
Old 05-21-2005, 04:29 PM   #4
<Ol>Origy
Member
 
Registered: Aug 2003
Location: Slovenia
Distribution: Arch, Debian, Embedded
Posts: 136

Original Poster
Rep: Reputation: 15
This is bugging be because I've seen some applications work on other PC's that refused to work properly on my PC until I opened/forwarded the proper ports.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables port forwarding geoff3425 Slackware 13 12-20-2011 10:50 AM
IPCHAINS port forwarding and IPTABLES port forwarding ediestajr Linux - Networking 26 01-14-2007 07:35 PM
iptables port forwarding question burnt_toast Linux - Networking 9 03-15-2005 08:26 AM
Iptables -- Port Forwarding slack_baby Linux - Networking 3 06-03-2004 02:29 PM
Iptables port forwarding question Renfro Linux - Security 1 10-11-2003 07:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration