Quoting mulyadi santosa <[EMAIL PROTECTED]>:

> CMR> benar pake NAT, tepatnya lagi menggunakan DNAT.
> CMR> misal:
> 
> anda benar, pake DNAT
> 
> CMR> $IPT -t nat -A PREROUTING -p tcp -d $SERVER_SMTP --dport 110 -j DNAT \
> CMR> --to-destination $SERVER_POP:110
> bisa dijelaskan knp pake PREROUTING?? saya baca HOWTO tapi masih butuh
> pencerahan lagi :-)

karena begini, man iptables:

   DNAT
       This  target is only valid in the nat table, in the PREROUTING and OUT-
                                                           ^^^^^^^^^^
       PUT chains, and user-defined chains which are only  called  from  those
       chains.  It specifies that the destination address of the packet should
       be modified (and all future packets in this  connection  will  also  be
       mangled), and rules should cease being examined.  It takes one option:

       --to-destination ipaddr[-ipaddr][:port-port]
              which can specify a single new destination IP address, an inclu-
              sive range of IP addresses, and optionally, a port range  (which
              is  only valid if the rule also specifies -p tcp or -p udp).  If
              no port range is specified, then the destination port will never
              be modified.

itu alasannya. 

tapi kalau pingin lebih jelas, lihat lagi urutan proses iptables, dari paket
yang mau masuk sampai yang dikeluarkan dari mesin.


Cecep Mahbub

-------------------------------------------------
This mail sent through IMP: http://horde.org/imp/

-- 
Utk berhenti langganan, kirim email ke [EMAIL PROTECTED]
Informasi arsip di http://www.linux.or.id/milis.php3

Kirim email ke