Koozali.org: home of the SME Server

Obsolete Releases => SME Server 8.x => Topic started by: andyw4 on September 23, 2012, 07:43:13 PM

Title: Custom port forward
Post by: andyw4 on September 23, 2012, 07:43:13 PM
Hi

Can anyone point me in the right direction of how to port forward a protocol other than TCP/UDP in Sme Server 8.0?

I can't do it via the web interface, so I guess I'm going to need to do it via the command line, but I don't know where to look.

I need a rule along the lines of:

-s 1.1.1.1 -d 2.2.2.2 -p ipv6-crypt -j ACCEPT

Thanks

A.
Title: Re: Custom port forward
Post by: CharlieBrady on September 23, 2012, 10:03:50 PM
Your only way to do this would be by custom template

I need a rule along the lines of:

-s 1.1.1.1 -d 2.2.2.2 -p ipv6-crypt -j ACCEPT

Such a rule doesn't do any forwarding. Assuming your external IP address is 2.2.2.2, then that rule would allow those packets through the iptables firewall, where SME server would then presumably reject them, because no software is waiting to deal with such a packet. If your external IP address is not 2.2.2.2, you wouldn't expect any such packets to arrive - the Internet wouldn't route those packets to your server.

What problem are you trying to solve?
Title: Re: Custom port forward
Post by: andyw4 on September 23, 2012, 10:14:08 PM
It does when it's combined with

-i eth1 -p ipv6-crypt -j DNAT --to-destination 192.168.10.10

added to the POSTROUTING chain.

I'm forwarding IPSEC traffic on to a PIX box internally that's handling a VON for en external support company. I know. I wouldn't have done it like this, but this is how the customer wants it, and how they had it with their SME 7.6 box.

The question is not what I'm trying to do, it's the original question - how do I add iptables rules that can not be handled by by the web interface?

A.

A.
Title: Re: Custom port forward
Post by: CharlieBrady on September 23, 2012, 11:33:56 PM
how do I add iptables rules that can not be handled by by the web interface?

I answered that question. Your only way to do this would be by custom template.
Title: Re: Custom port forward
Post by: janet on September 24, 2012, 02:35:01 AM
andyw4

Re adding a custom template for iptables rules:

A perusal of the available documentation on contribs.org would steer you here
http://wiki.contribs.org/Template_Tutorial#masq
and here
http://wiki.contribs.org/SME_Server:Documentation:Developers_Manual#Configuration_file_templates