RE: [suse-security] Another NAT Question
-----Original Message----- From: BLeonhardt@analytek.de [mailto:BLeonhardt@analytek.de] Sent: 10 December 2003 14:35 To: suse-sec Subject: [suse-security] Another NAT Question HI all, I'm not sure about the PREROUTING chain .. if I say : iptables -t nat -A PREROUTING -i eth1 -o eth0 -p tcp --dport 80 -j DNAT --to-destination 172.16.15.12:8080 is the real source address present or the source address from the router ? cu bruno -- Check the headers for your unsubscription address For additional commands, e-mail: suse-security-help@suse.com Security-related bug reports go to security@suse.de, not here Before pre-routing - the real source address After pre-routing when the packet hits the FORWARD chain - the source ip of the router.
participants (1)
-
Raymond Leach