On 6/8/11 6:30 AM, Sharif Uddin wrote:

> I am having problems forwarding from public vip to private vip and back
> 
> *configuration files*

Note that http://www.shorewall.net/support.htm#Guidelines specifically
asks that you not send configuration files.

> 
> DNAT        net         loc:192.168.0.237  tcp  ssh,80,443            #works
> [/CODE]
> 
> In the above my public vip is 195.x.x.21, but i am using a real server
> ip (192.168.0.237) and it works. BUT if i use 192.168.0.199 which is the
> private vip on the same box it does not work.

If it is on the same box, you DNAT rule needs to be:

DNAT    net     $FW:192.168.0.199
                ---

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
EditLive Enterprise is the world's most technically advanced content
authoring tool. Experience the power of Track Changes, Inline Image
Editing and ensure content is compliant with Accessibility Checking.
http://p.sf.net/sfu/ephox-dev2dev
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to