Thanks for your reply
Yes, I did put:
DNAT net loc:192.168.1.2 tcp 80
(typo mistake, it should 192.168.1.2 -not- 192.168.168.2)

When I type my external IP from my ISP, it will hit the Apache on Shorewall 
(192.168.1.1)
Where is should  hit my Apache on the other box (192.168.1.2)

Cheers



----- Original Message ----
From: Tom Eastep <[email protected]>
To: Shorewall Users <[email protected]>
Sent: Friday, 19 June, 2009 2:12:09 AM
Subject: Re: [Shorewall-users] Redirect port 80 away from Shorewall?

Phillipus Gunawan wrote:
> Hi There,
> 
> Due to shortage computer, I need to install Apache to my Shorewall box 
> (192.168.1.1)
> But the real web server is on another box (192.168.1.2)
> I tried to put rule:
> 
> DNAT net loc:192.168.168.1 tcp 80
> 
> But everytime www connection coming in, it will hit my shorewall
> 
> Any solution?

Sorry -- I don't fully understand the problem.

Do you also have this rule to forward web traffic to 192.168.1.2?

    DNAT    net    loc:192.168.1.2    tcp    80

If so, then to access the web server on the Shorewall system, you need
to either always use it's internal IP address (192.168.1.1) or you need
to forward a different port to it such as:

    REDIRECT    net    80    tcp    81

Hope this helps,
-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,        \ died peacefully in his sleep. Not screaming like
Washington, USA    \ all of the passengers in his car
http://shorewall.net \________________________________________________


      Access Yahoo!7 Mail on your mobile. Anytime. Anywhere.
Show me how: http://au.mobile.yahoo.com/mail

------------------------------------------------------------------------------
Crystal Reports - New Free Runtime and 30 Day Trial
Check out the new simplified licensing option that enables unlimited
royalty-free distribution of the report engine for externally facing 
server and web deployment.
http://p.sf.net/sfu/businessobjects
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to