Also, you might want to look into Bind 9 and DNS Zones - that's how I solved my problem.  The external users see one IP address for a particular domain name - the public one -, and the internal users see another IP (private) for the same server.  Thus, they learn to call things "by their right name", and leave it to us geeky engineer IT über god guys to do the magic.

:)

Cheers.

Michael Weickel - iQom Business Services GmbH wrote:
This is Shorewall FAQ 2 -- you only have to change the ports (FAQ is about
smtp)

A dirty hack (but works too) is to change /etc/hosts on the affected
internally machines to redirect to internally rather than externally

-----Ursprüngliche Nachricht-----
Von: Matt Harrison [mailto:[email protected]] 
Gesendet: Sonntag, 30. August 2009 15:53
An: Shorewall Users
Betreff: [Shorewall-users] redirecting internal traffic

Hi all,

This is a bit silly, but I've been puzzling over it for a few hours now.

We've got a shorewall box running, doing well. One of the things it does 
it redirect all outbound http traffic to the squid proxy on port 3128.

Recently we've installed a service that requires external users to 
connect to an internal machine via DNAT'ing, which is working well. The 
problem is that the service registers our IP (external) address with a 
central server, meaning that internal users are unable to access it.

I'm looking for some way to redirect traffic destined for a specific 
port(s) on the firewall to another internal machine.

I'm not totally sure I've made myself clear so please ask for 
clarification if necessary, we'd love to get this sorted.

Many thanks


Matt

----------------------------------------------------------------------------
--
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus
on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users


------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users
  

--
Diego Rivera
Director / System Operations
Roundbox Global : enterprise : technology : genius
------------------------------------------------------------------------------------------------------------------
Avenida 11 y Calle 7-9, Barrio Amón, San José, Costa Rica
tel: +1 (404) 567-5000 ext. 2147 | cel: +(506) 8393-0772 | fax: +(506) 2258-3695
email: [email protected] | www.rbxglobal.com
------------------------------------------------------------------------------------------------------------------

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to