12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using IPTables Target Extensions 497MASQUERADEMasquerade the IP address of the network interface from which the packet isleaving. Connections are forgotten when the interface goes down. Only for dialupconnections without a static IP address. For static IPs, use the SNAT target. Can onlybe used with the nat table in the POSTROUTING chain.--to-ports -Range of source ports to use. Only works if -p tcp or -p udp is used.MIRRORNETMAPInvert the source and destination fields in the IP header and send the packetagain. Can only be used in the INPUT, FORWARD, and PREROUTING chains or userdefinedchains called from these chains. Experimental.24Statically map a network of address onto another one. Only works with the nat table.--to /Which network address on which to map. The mask is optional.NFQUEUEExtension of the QUEUE target. Allows the packet to be placed in a specific queue.--queue-num 16-bit queue number in which to place the packet, from 0 to 65535. Defaults to 0.NOTRACKDisable connection tracking for packets matching the rule. Only works with theraw table.REDIRECT<strong>Red</strong>irect packet to the local host by modifying the destination IP to the primaryaddress of the incoming network interface. Only works with the nat table in thePREROUTING and OUTPUT chains or a user-defined chain called from these chains.--to-ports -Individual destination port or port range. Must only be used with -p tcp or -pudp.REJECTIf packet matches, an error packet is sent back as a response. Only works with theINPUT, FORWARD, and OUTPUT chains or a user-defined chain called from these chains.--reject-with

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!