Mám to uložené rovnako ako pri prístupe na server za routerom ku ktorému prístup funguje:
config redirect
option target 'DNAT'
option dest 'lan'
option name 'turris'
option dest_ip '192.168.1.1'
option src 'wan'
option proto 'tcp'
option src_dport '443'
option dest_port '443'
žiaľ ak tam dám IP turrisu tak to proste nebeží. Žiaľ v tejto problematike som stále začiatočník. Po uložené neevidujem zmenu v nastavení:
# Generated by iptables-save v1.4.20 on Thu Oct 30 13:47:06 2014
*nat
:PREROUTING ACCEPT [633:109305]
:INPUT ACCEPT [36:6193]
:OUTPUT ACCEPT [56:6514]
:POSTROUTING ACCEPT [30:4510]
:MINIUPNPD - [0:0]
:delegate_postrouting - [0:0]
:delegate_prerouting - [0:0]
:postrouting_lan_rule - [0:0]
:postrouting_rule - [0:0]
:postrouting_wan_rule - [0:0]
:prerouting_lan_rule - [0:0]
:prerouting_rule - [0:0]
:prerouting_wan_rule - [0:0]
:zone_lan_postrouting - [0:0]
:zone_lan_prerouting - [0:0]
:zone_wan_postrouting - [0:0]
:zone_wan_prerouting - [0:0]
-A PREROUTING -j delegate_prerouting
-A POSTROUTING -j delegate_postrouting
-A delegate_postrouting -m comment --comment "user chain for postrouting" -j postrouting_rule
-A delegate_postrouting -o br-lan -j zone_lan_postrouting
-A delegate_postrouting -o br-wan -j zone_wan_postrouting
-A delegate_prerouting -m comment --comment "user chain for prerouting" -j prerouting_rule
-A delegate_prerouting -i br-lan -j zone_lan_prerouting
-A delegate_prerouting -i br-wan -j zone_wan_prerouting
-A zone_lan_postrouting -m comment --comment "user chain for postrouting" -j postrouting_lan_rule
-A zone_lan_postrouting -s 192.168.1.0/24 -d 192.168.1.234/32 -p tcp -m tcp --dport 8080 -m comment --comment "eHDD (reflection)" -j SNAT --to-source 192.168.1.1
-A zone_lan_prerouting -m comment --comment "user chain for prerouting" -j prerouting_lan_rule
-A zone_lan_prerouting -s 192.168.1.0/24 -d 10.109.8.237/32 -p tcp -m tcp --dport 8080 -m comment --comment "eHDD (reflection)" -j DNAT --to-destination 192.168.1.234:8080
-A zone_wan_postrouting -m comment --comment "user chain for postrouting" -j postrouting_wan_rule
-A zone_wan_postrouting -j MASQUERADE
-A zone_wan_prerouting -i br-wan -j MINIUPNPD
-A zone_wan_prerouting -m comment --comment "user chain for prerouting" -j prerouting_wan_rule
-A zone_wan_prerouting -p tcp -m tcp --dport 8080 -m comment --comment eHDD -j DNAT --to-destination 192.168.1.234:8080
-A zone_wan_prerouting -p tcp -m tcp --dport 443 -m comment --comment turris -j REDIRECT --to-ports 443
-A zone_wan_prerouting -p tcp -m tcp --dport 22 -m comment --comment SSH -j REDIRECT --to-ports 22
COMMIT
# Completed on Thu Oct 30 13:47:06 2014
# Generated by iptables-save v1.4.20 on Thu Oct 30 13:47:06 2014
*raw
:PREROUTING ACCEPT [2746:721357]
:OUTPUT ACCEPT [854:252584]
:delegate_notrack - [0:0]
-A PREROUTING -j delegate_notrack
COMMIT
# Completed on Thu Oct 30 13:47:06 2014
# Generated by iptables-save v1.4.20 on Thu Oct 30 13:47:06 2014
*mangle
:PREROUTING ACCEPT [2746:721357]
:INPUT ACCEPT [869:136367]
:FORWARD ACCEPT [1690:524335]
:OUTPUT ACCEPT [856:253064]
:POSTROUTING ACCEPT [2547:777735]
:fwmark - [0:0]
:mssfix - [0:0]
-A PREROUTING -j fwmark
-A FORWARD -j mssfix
-A mssfix -o br-wan -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "wan (mtu_fix)" -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Thu Oct 30 13:47:06 2014
# Generated by iptables-save v1.4.20 on Thu Oct 30 13:47:06 2014
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:MINIUPNPD - [0:0]
:accept - [0:0]
:delegate_forward - [0:0]
:delegate_input - [0:0]
:delegate_output - [0:0]
:forwarding_lan_rule - [0:0]
:forwarding_rule - [0:0]
:forwarding_wan_rule - [0:0]
:input_lan_rule - [0:0]
:input_rule - [0:0]
:input_wan_rule - [0:0]
:output_lan_rule - [0:0]
:output_rule - [0:0]
:output_wan_rule - [0:0]
:reject - [0:0]
:syn_flood - [0:0]
:turris - [0:0]
:zone_lan_dest_accept - [0:0]
:zone_lan_forward - [0:0]
:zone_lan_input - [0:0]
:zone_lan_output - [0:0]
:zone_lan_src_accept - [0:0]
:zone_wan_dest_REJECT - [0:0]
:zone_wan_dest_accept - [0:0]
:zone_wan_forward - [0:0]
:zone_wan_input - [0:0]
:zone_wan_output - [0:0]
:zone_wan_src_REJECT - [0:0]
-A INPUT -j delegate_input
-A FORWARD -j delegate_forward
-A OUTPUT -j delegate_output
-A accept -o br-wan -j turris
-A accept -j ACCEPT
-A delegate_forward -m comment --comment "user chain for forwarding" -j forwarding_rule
-A delegate_forward -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A delegate_forward -i br-lan -j zone_lan_forward
-A delegate_forward -i br-wan -j zone_wan_forward
-A delegate_forward -j reject
-A delegate_input -i lo -j ACCEPT
-A delegate_input -m comment --comment "user chain for input" -j input_rule
-A delegate_input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A delegate_input -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn_flood
-A delegate_input -i br-lan -j zone_lan_input
-A delegate_input -i br-wan -j zone_wan_input
-A delegate_input -j accept
-A delegate_output -o lo -j ACCEPT
-A delegate_output -m comment --comment "user chain for output" -j output_rule
-A delegate_output -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A delegate_output -o br-lan -j zone_lan_output
-A delegate_output -o br-wan -j zone_wan_output
-A delegate_output -j accept
-A reject -p tcp -j REJECT --reject-with tcp-reset
-A reject -j REJECT --reject-with icmp-port-unreachable
-A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -j RETURN
-A syn_flood -j DROP
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00005E11_l_a_4_X dst -j LOG --log-prefix "turris-00005E11: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_000E7E01_l_a_4_X dst -j LOG --log-prefix "turris-000E7E01: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00415B11_l_a_4_X dst -j LOG --log-prefix "turris-00415B11: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00557B71_l_ap_4_X dst,dst -j LOG --log-prefix "turris-00557B71: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_007E0511_l_a_4_X dst -j LOG --log-prefix "turris-007E0511: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_009A7E41_l_a_4_X dst -j LOG --log-prefix "turris-009A7E41: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00A07051_l_a_4_X dst -j LOG --log-prefix "turris-00A07051: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00A704A1_l_a_4_X dst -j LOG --log-prefix "turris-00A704A1: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00CE6700_lb_ap_4_X dst,dst -j LOG --log-prefix "turris-00CE6700: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00CE6701_l_a_4_X dst -j LOG --log-prefix "turris-00CE6701: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00CE6701_l_ap_4_X dst,dst -j LOG --log-prefix "turris-00CE6701: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00D05711_l_a_4_X dst -j LOG --log-prefix "turris-00D05711: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_00FE0D01_l_a_4_X dst -j LOG --log-prefix "turris-00FE0D01: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_047C0DE1_l_a_4_X dst -j LOG --log-prefix "turris-047C0DE1: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_06E7E701_l_a_4_X dst -j LOG --log-prefix "turris-06E7E701: " --log-level 7
-A turris -o br-wan -m limit --limit 1/sec -m set --match-set turris_0A566041_l_ap_4_X dst,dst -j LOG --log-prefix "turris-0A566041: " --log-level 7
-A turris -o br-wan -m set --match-set turris_00CE6700_lb_ap_4_X dst,dst -j DROP
-A zone_lan_dest_accept -o br-lan -j accept
-A zone_lan_forward -m comment --comment "user chain for forwarding" -j forwarding_lan_rule
-A zone_lan_forward -m comment --comment "forwarding lan -> wan" -j zone_wan_dest_accept
-A zone_lan_forward -m conntrack --ctstate DNAT -m comment --comment "Accept port forwards" -j accept
-A zone_lan_forward -j zone_lan_dest_accept
-A zone_lan_input -m comment --comment "user chain for input" -j input_lan_rule
-A zone_lan_input -m conntrack --ctstate DNAT -m comment --comment "Accept port redirections" -j accept
-A zone_lan_input -j zone_lan_src_accept
-A zone_lan_output -m comment --comment "user chain for output" -j output_lan_rule
-A zone_lan_output -j zone_lan_dest_accept
-A zone_lan_src_accept -i br-lan -j accept
-A zone_wan_dest_REJECT -m limit --limit 1/sec -j LOG --log-prefix "turris-000000: " --log-level 7
-A zone_wan_dest_REJECT -o br-wan -j reject
-A zone_wan_dest_accept -o br-wan -j accept
-A zone_wan_forward -i br-wan ! -o br-wan -j MINIUPNPD
-A zone_wan_forward -m comment --comment "user chain for forwarding" -j forwarding_wan_rule
-A zone_wan_forward -m conntrack --ctstate DNAT -m comment --comment "Accept port forwards" -j accept
-A zone_wan_forward -j zone_wan_dest_REJECT
-A zone_wan_input -m comment --comment "user chain for input" -j input_wan_rule
-A zone_wan_input -p udp -m udp --dport 68 -m comment --comment Allow-DHCP-Renew -j accept
-A zone_wan_input -p icmp -m icmp --icmp-type 8 -m comment --comment Allow-Ping -j accept
-A zone_wan_input -m conntrack --ctstate DNAT -m comment --comment "Accept port redirections" -j accept
-A zone_wan_input -j zone_wan_src_REJECT
-A zone_wan_output -m comment --comment "user chain for output" -j output_wan_rule
-A zone_wan_output -j zone_wan_dest_accept
-A zone_wan_src_REJECT -m limit --limit 1/sec -j LOG --log-prefix "turris-000000: " --log-level 7
-A zone_wan_src_REJECT -i br-wan -j reject
COMMIT
# Completed on Thu Oct 30 13:47:06 2014