diff --git a/nixos/hosts/osaka-linode-01/firewall.nix b/nixos/hosts/osaka-linode-01/firewall.nix index f6777609..5da4b865 100644 --- a/nixos/hosts/osaka-linode-01/firewall.nix +++ b/nixos/hosts/osaka-linode-01/firewall.nix @@ -21,30 +21,13 @@ 5280 # Jitsi ]; + + # https://www.digitalocean.com/community/tutorials/how-to-forward-ports-through-a-linux-gateway-with-iptables networking.firewall.extraCommands = '' iptables -F iptables -t nat -F iptables -X - # iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT - - iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2:25 - iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 25 -j SNAT --to-source 172.234.84.222 - - iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2:465 - iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 465 -j SNAT --to-source 172.234.84.222 - - iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2:587 - iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 587 -j SNAT --to-source 172.234.84.222 - - iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2:143 - iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 143 -j SNAT --to-source 172.234.84.222 - - iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2:993 - iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 993 -j SNAT --to-source 172.234.84.222 - - iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2:4190 - iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 4190 -j SNAT --to-source 172.234.84.222 - + iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT # TCP PORTS ################################################################################################## # PORT 80 @@ -55,29 +38,29 @@ iptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2 iptables -t nat -A POSTROUTING -p tcp --dport 443 -j MASQUERADE - # # PORT 25 - # iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 - # iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE - # - # # PORT 465 - # iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 - # iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE - # - # # PORT 587 - # iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 - # iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE - # - # # PORT 143 - # iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 - # iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE - # - # # PORT 993 - # iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 - # iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE - # - # # PORT 4190 - # iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 - # iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE + # PORT 25 + iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE + + # PORT 465 + iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE + + # PORT 587 + iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE + + # PORT 143 + iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE + + # PORT 993 + iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE + + # PORT 4190 + iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 + iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE # PORT 42420 iptables -t nat -A PREROUTING -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2