Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

shorewall redirect

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
9 posts • Page 1 of 1
Author
Message
hegga
Apprentice
Apprentice
Posts: 210
Joined: Wed Jun 04, 2003 10:30 am
Location: Norway
Contact:
Contact hegga
Website

shorewall redirect

  • Quote

Post by hegga » Fri Nov 10, 2006 10:59 am

I want to redirect all outgoing smtp traffic from my network to my internal
mailserver. does anyone know howto do that with shorewall?
hegga
Top
bunder
Bodhisattva
Bodhisattva
Posts: 5956
Joined: Sat Apr 10, 2004 5:13 am

Re: shorewall redirect

  • Quote

Post by bunder » Fri Nov 10, 2006 11:28 am

hegga wrote:I want to redirect all outgoing smtp traffic from my network to my internal
mailserver. does anyone know howto do that with shorewall?
make a rule that sets all traffic with a destination of your external network card which forwards destination port 25 to the mail server.

something like: iptables -A -i externalip -p 25 -d ipaddress -j FORWARD
Neddyseagoon wrote:The problem with leaving is that you can only do it once and it reduces your influence.
banned from #gentoo since sept 2017
Top
hegga
Apprentice
Apprentice
Posts: 210
Joined: Wed Jun 04, 2003 10:30 am
Location: Norway
Contact:
Contact hegga
Website

  • Quote

Post by hegga » Fri Nov 10, 2006 11:34 am

Perhaps I was a bit unclear in my question, I want all my outgoing smtp traffic from
my internal network to be redirected through my internal mailserver.

in other words, it shall not be possible to send emails from my internal network without
it going through my internal mailserver.
hegga
Top
bunder
Bodhisattva
Bodhisattva
Posts: 5956
Joined: Sat Apr 10, 2004 5:13 am

  • Quote

Post by bunder » Fri Nov 10, 2006 11:49 am

yes, it should work... maybe you don't need the "-i externalip" bit, but that should do it.

edit: you could always set the source network card(s), that should also help force it.
Neddyseagoon wrote:The problem with leaving is that you can only do it once and it reduces your influence.
banned from #gentoo since sept 2017
Top
hegga
Apprentice
Apprentice
Posts: 210
Joined: Wed Jun 04, 2003 10:30 am
Location: Norway
Contact:
Contact hegga
Website

  • Quote

Post by hegga » Fri Nov 10, 2006 12:00 pm

thanx, but do you know how to do it in shorewall also?
hegga
Top
bunder
Bodhisattva
Bodhisattva
Posts: 5956
Joined: Sat Apr 10, 2004 5:13 am

  • Quote

Post by bunder » Fri Nov 10, 2006 10:22 pm

sorry, i'm afraid i don't... shorewall uses a different configuration than i'm familiar with.
Neddyseagoon wrote:The problem with leaving is that you can only do it once and it reduces your influence.
banned from #gentoo since sept 2017
Top
Bobnoxous
Apprentice
Apprentice
User avatar
Posts: 240
Joined: Tue May 03, 2005 2:00 am

  • Quote

Post by Bobnoxous » Sat Nov 11, 2006 12:52 am

I'm curious, but won't that rule prevent the mail from getting out of the network from the mail server too? You would need to exclude the IP of the server I think. I realize we're getting off the shorewall topic, but the issue would apply to shorewall rules too.
"The problem with the world is that fools and fanatics are always so sure of themselves while wiser people are so full of doubt."
- Bertrand Russell
Top
hegga
Apprentice
Apprentice
Posts: 210
Joined: Wed Jun 04, 2003 10:30 am
Location: Norway
Contact:
Contact hegga
Website

  • Quote

Post by hegga » Sat Nov 11, 2006 10:32 am

I tried using this rule in /etc/shorewall/rules, but it blocked the smtp connections from
the server as well.

Code: Select all

DNAT   local   local:server-ip:25     tcp     25      -       !server-ip
If I'm trying with shorewall redirect I get an error message

Code: Select all

REDIRECT       local   local:server-ip:25     tcp     25      -       !server-ip
hegga
Top
hegga
Apprentice
Apprentice
Posts: 210
Joined: Wed Jun 04, 2003 10:30 am
Location: Norway
Contact:
Contact hegga
Website

  • Quote

Post by hegga » Mon Nov 13, 2006 8:09 pm

is there no shorewall expert to give me a tip about this?
hegga
Top
Post Reply

9 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic