From 82fc2c04489c048ca215b71c132423cb217695ed Mon Sep 17 00:00:00 2001 From: iFargle Date: Thu, 7 Dec 2023 00:16:48 +0900 Subject: [PATCH] test --- nixos/hosts/osaka-linode-01/firewall.nix | 65 +++++++++++++++--------- 1 file changed, 42 insertions(+), 23 deletions(-) diff --git a/nixos/hosts/osaka-linode-01/firewall.nix b/nixos/hosts/osaka-linode-01/firewall.nix index 50a2925d..f48ec797 100644 --- a/nixos/hosts/osaka-linode-01/firewall.nix +++ b/nixos/hosts/osaka-linode-01/firewall.nix @@ -24,6 +24,25 @@ networking.firewall.extraCommands = '' iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT + iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2:25 + iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 25 -j SNAT --to-source 172.234.84.222 + + iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2:465 + iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 465 -j SNAT --to-source 172.234.84.222 + + iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2:587 + iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 587 -j SNAT --to-source 172.234.84.222 + + iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2:143 + iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 143 -j SNAT --to-source 172.234.84.222 + + iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2:993 + iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 993 -j SNAT --to-source 172.234.84.222 + + iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2:4190 + iptables -t nat -A POSTROUTING -p tcp -d 10.100.0.2 --dport 4190 -j SNAT --to-source 172.234.84.222 + + # TCP PORTS ################################################################################################## # PORT 80 iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination 10.100.0.2 @@ -33,29 +52,29 @@ iptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2 iptables -t nat -A POSTROUTING -p tcp --dport 443 -j MASQUERADE - # PORT 25 - iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE - - # PORT 465 - iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE - - # PORT 587 - iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE - - # PORT 143 - iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE - - # PORT 993 - iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE - - # PORT 4190 - iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE + # # PORT 25 + # iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 + # iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE + # + # # PORT 465 + # iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 + # iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE + # + # # PORT 587 + # iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 + # iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE + # + # # PORT 143 + # iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 + # iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE + # + # # PORT 993 + # iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 + # iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE + # + # # PORT 4190 + # iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 + # iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE # PORT 42420 iptables -t nat -A PREROUTING -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2