help with PREROUTING --to-destination problem

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

Threaded View
I have a box which has 2 ethernet cards, basically its IPCop.
Im trying to do the following:

// 1. send all port 80 traffic to the apache server at port 81 (works)
iptables -A PREROUTING -t nat -p tcp -d 0/0 --dport 80 -J DNAT --to-

// 2. allow a single user IP to get to the web now (also works)
iptables -I PREROUTING 1 -t nat -p tcp -s --dport 80 -j

// 3. now the problem, I do the following to delete the client from
step 2
// but it (the browser) hangs trying to connect to whatever website I
iptables -D PREROUTING -t nat -p tcp -s --dport 80 -j

Can someone tell me whats wrong with step 3 to get the redirect in
step 1 to
work again for the client?

Thanks in advance

Re: help with PREROUTING --to-destination problem

Am Wed, 17 Dec 2008 10:28:28 -0800 schrieb Jeff:

Quoted text here. Click to load it

Your first rule has source 0/0 either (your second rule will never match),
put the 2nd rule above your first, then it should work.
You can check it via iptable -t nat -L -n ans you'll see the matching


Site Timeline