Project

General

Profile

Evolution #1543

Ajout d'un type de directive "translation"

Added by Fabrice Barconnière about 10 years ago. Updated almost 10 years ago.

Status:
Fermé
Priority:
Haut
Assigned To:
Category:
-
Start date:
03/14/2011
Due date:
% Done:

100%

Spent time:
Distribution:

Description

iptables -t nat -D POSTROUTING -s %%adresse_network_eth2/%%adresse_netmask_eth2 -o eth0 -d ADRESSE_RESEAU_DST/ADRESSE_NETMASK_DST -j SNAT --to %%adresse_ip_eth1

iptables -I FORWARD -s %%adresse_network_eth2/%%adresse_netmask_eth2 -i eth1 -d ADRESSE_RESEAU_DST/ADRESSE_NETMASK_DST -o eth0 -j ACCEPT

iptables -I FORWARD -s %%adresse_network_eth2/%%adresse_netmask_eth2 -i eth1 -d ADRESSE_RESEAU_DST/ADRESSE_NETMASK_DST -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT

History

#1 Updated by Gwenael Remond about 10 years ago

  • Status changed from Nouveau to Résolu
  • Priority changed from Normal to Haut
  • % Done changed from 0 to 100

Era contient maintenant un nouveau type de directive, le type translation, qui permet de générer ces trois règles en même temps.

#2 Updated by Gwenael Remond about 10 years ago

  • Target version changed from 76 to 95

#3 Updated by Fabrice Barconnière about 10 years ago

Voici les types de règles à générer pour la directive de type translation:

iptables -t nat -I POSTROUTING -s 172.16.0.0/24 -d 172.30.107.0/25 -o eth0 -m state --state NEW -j SNAT --to-source 10.21.11.1

iptables -t nat -I POSTROUTING -s 172.16.0.0/24 -d 172.30.107.0/25 -o eth0 -m state --state RELATED,ESTABLISHED -j SNAT --to-source 10.21.11.1

iptables -I FORWARD -s 172.16.0.0/24 -d 172.30.107.0/25 -o eth0 -m state --state NEW -m policy --dir out --pol ipsec --proto esp -j ACCEPT

iptables -I FORWARD -s 172.16.0.0/24 -d 172.30.107.0/25 -o eth0 -m state --state RELATED,ESTABLISHED -m policy --dir out --pol ipsec --proto esp -j ACCEPT

#4 Updated by Joël Cuissinat almost 10 years ago

  • Target version changed from 95 to EOLE 2.3 Stable

#5 Updated by Jerome Soyer almost 10 years ago

  • Status changed from Résolu to Fermé

Also available in: Atom PDF