netfilter .. (openswan) nat problem ..
jietoh at o2online.de
Tue Jun 6 23:00:39 CEST 2006
i have to solv the following problem (debian 3.1, kernel 2.6.14 from kernel
org, no patches, openswan 2.x.x maybe important):
netA - gwA - gwB - netB - internet, where
gwA: 192.168.0.1 + pppoe-ip-addr
gwB: 100.100.100.100 (static official ip)
netB: 100.100.100.100/32 (no real subnet)
gwA and gwB are both real gateways
tunnel works in the following way:
netA/gwA to netB/gwB and netB/gwB to netA/gwA, all I think .
now I want to forward a spezial port on gwB, perhaps 50000 to an address in
netA (192.168.0.100:50000), ok np from gwB, but ! I could not connect from
the internet over gwB to this spezial host
my nat rules, nothing else ..
iptables -t nat -A PREROUTING -j DNAT -p tcp -s 0/0 --dport 50000
--to-destination 192.168.0.100:50000 -i eth0
iptables -t nat -A POSTROUTING -j SNAT -p tcp -d 192.168.0.100 --dport 50000
--to 100.100.100.100 -o eth0
tcpdump tell me that all nat works, but no traffic on gwA interfaces
received. gwB send it, but I have a [DF] in that lines, maybe important, I
any suggestions? someone could help?
More information about the netfilter