News: This forum is now permanently frozen.
Pages: [1]
Topic: Configure NAT port 80 public to port 22 private  (Read 2431 times)
« on: September 24, 2009, 12:04:09 »
russbutton *
Posts: 2

I'm new to m0n0wall, but have used DLink NAT boxes for years.  I just built up a m0n0wall on a mini-itx box with an ide based flash drive.  I'm using version 1.235 of m0n0wall.

I want to create a NAT mapping from my WAN side port 80 to a specific Linux host inside at port 22.  The reason for this is that where I work, everything goes out through the company proxy server, which only allows traffic out port 80. 

With the DLink NAT box, I could use ssh through the proxy server to port 80 and get forwarded to port 22 at my Linux box inside.

I put up jpg images of the rules config page, firewall rules page and the firewall log on my website at:

http://www.russbutton.com/tmp/   

When I attempt to ssh from a machine with a public IP addr, it appears I'm getting rejected.  What am I missing?  This shouldn't be all that hard.


* firewall_log.jpg (16.93 KB, 400x136 - viewed 301 times.)
« Reply #1 on: September 24, 2009, 15:09:22 »
Fred Grayson *****
Posts: 994

In your picture firewall rules you have source port 80. This is wrong. It must be any (*).

--
Google is your friend and Bob's your uncle.
« Reply #2 on: September 24, 2009, 17:16:28 »
markb ****
Posts: 331

The simplest way, is to set up the NAT and let it create the rule for you.  On the WAN interface select port 80 then enter the IP address of the linux box and port 22.  Check the box to auto add the rule.  Click OK and then goto your rules page and move the rule to the appropriate place in the list.  (I believe it puts it at the bottom by default)
« Reply #3 on: September 24, 2009, 17:41:28 »
russbutton *
Posts: 2

Thanks markb.  That did the trick.   I had tried using the NAT dialog before to create a rule, but had not activated it on the Rules page. 

At work, I'm required to live on a Windows desktop, so I use putty to ssh into my home system over public port 80, and while I do that, I'm also creating some tunnels to access other services I have in my home environment.   

Thanks again for the help.
« Reply #4 on: September 25, 2009, 16:43:50 »
markb ****
Posts: 331

Glad it worked.  Remember you can only set up one inbound NAT per port for a single IP address.   If you want to get into other ports inside your network over port 80, you will require additional IP addresses on your WAN.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines