Untitled
By: a guest | Mar 19th, 2010 | Syntax:
None | Size: 0.80 KB | Hits: 31 | Expires: Never
BEN="10.0.8.49"
VM="10.0.8.47"
WAN="##"
LAN="10.0.8.50"
WANDEV="eth0"
LANDEV="eth1"
#Flush old rules
/sbin/iptables -F
/sbin/iptables -X
/sbin/iptables -Z
/sbin/iptables -t nat -F
#enable routing
/bin/echo "1" > /proc/sys/net/ipv4/ip_forward
#Set up SNAT
iptables -t nat -A POSTROUTING -o eth0 -s 10.0.8.0/24 -j SNAT --to $WAN
iptables -t nat -A POSTROUTING -o eth1 -m conntrack --ctstate DNAT -j LOG --log-prefix 'conntrack'
iptables -t nat -A POSTROUTING -o eth1 -m conntrack --ctstate DNAT -j SNAT --to-source $WAN
#PREROUTING rules
#DNS
/sbin/iptables -t nat -A PREROUTING -i eth1 -p udp --dport 53 -j DNAT --to 68.94.157.1:53
#WEB SERVER
#/sbin/iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j LOG
/sbin/iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to $VM:80