Iptables packet forwarding vs NATMarking packets with iptables with a NATLinux IPTables Destination NAT with Asymmetrical Routing?iptables port forwardingiptables NAT with multiple interfacesNAT, iptables and problematic portsNAT / Port Forwarding with iptables firewallHow to configure iptables rules for connecting 2 eth to the net (forwarding & masquerading)CentOS, dual route, natiptables foward to multiple interfaces with NATBlock linux bridge traffic (only one way) using iptables or ebtables

What is the color associated with lukewarm?

Do items with curse of vanishing disappear from shulker boxes?

Why is gun control associated with the socially liberal Democratic party?

Is it possible to install Firefox on Ubuntu with no desktop enviroment?

How do you translate “talk shit”?

How can I detect if I'm in a subshell?

Do legislators hold the right of legislative initiative?

The last tree in the Universe

Nth term of Van Eck Sequence

Can Dive Down protect a creature against Pacifism?

Idiom for 'person who gets violent when drunk"

What should I be aware of in buying second-hand sinks and toilets?

Is it a good security practice to force employees hide their employer to avoid being targeted?

How do credit card companies know what type of business I'm paying for?

Are there any rules for identifying what spell an opponent is casting?

How many times to repeat an event with known probability before it has occurred a number of times

Digital signature that is only verifiable by one specific person

Is it unethical to quit my job during company crisis?

Is there a risk to write an invitation letter for a stranger to obtain a Czech (Schengen) visa?

Are athletes' college degrees discounted by employers and graduate school admissions?

Can I give my friend the sour dough "throw away" as a starter to their sourdough starter?

Is it possible to have battery technology that can't be duplicated?

How can Caller ID be faked?

Print the phrase "And she said, 'But that's his.'" using only the alphabet



Iptables packet forwarding vs NAT


Marking packets with iptables with a NATLinux IPTables Destination NAT with Asymmetrical Routing?iptables port forwardingiptables NAT with multiple interfacesNAT, iptables and problematic portsNAT / Port Forwarding with iptables firewallHow to configure iptables rules for connecting 2 eth to the net (forwarding & masquerading)CentOS, dual route, natiptables foward to multiple interfaces with NATBlock linux bridge traffic (only one way) using iptables or ebtables






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








-1















From what I have read on packet forwarding, in case of a multihomed host that is connected to two different networks, packet forwarding allows packets to travel from one network to another through its two network interfaces.



Given the above, I have a Raspberry Pi setup with its WiFi connected to the Internet via a router. The WiFi interface has an IP address of 10.0.0.10 obtained via DHCP from the router. I have the RPI's Ethernet interface connected to a computer. The Ethernet interface has a static IP address of 192.168.0.1 and the computer obtains an IP address 192.168.0.15 from the DHCP server running on the RPI. The setup looks like this:



Router[10.0.0.1] <--> RPI WiFi[10.0.0.10] <--> RPI Ethernet[192.168.0.1] <--> PC[192.168.0.15]



Going by the definition of packet forwarding for a multihomed host, on applying the following Iptable rules that forwards packets from RPI's Ethernet to WiFi, I expect the computer to be able to ping the router [10.0.0.1] and also connect to the Internet.



iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT
iptables -A FORWARD -i wlan0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT



However, things do not work as I expected. Whereas, on removing the above rules and adding the NAT rule:



iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE



The computer is able to connect to the Internet.



  • Why doesn't the packet forwarding work?

  • Or if it works why can't I ping or get the computer to access the Internet?

  • What would I need to do to have all traffic on the Ethernet interface go out via the WiFi?

Note: I have forwarding enabled on the RPI.










share|improve this question

















  • 1





    You need the masquerade because the router has no idea that the 192.168.0.0/24 network is reachable via the raspberry pi. Masquerade changes the address to that of the pi, which the router knows how to reach (it's the same local network).

    – yoonix
    May 30 at 17:57











  • @yoonix Just to re-phrase, what you are saying is the computer is able to reach the router via forwarding, however, the router itself is not able to respond to the ping or send the requested webpage back to the computer as it cannot reach the 192.168.0.0/24 network? Then a question arises, can we masquerade without NATting? What other options do we have to enable cross communication?

    – John
    May 30 at 18:07











  • @John, you would need to add a route to the router so that it knows that it can reach the 192.168.0.0/24 network via the RPi. The steps for doing that depend greatly on your router model, and may in fact not be possible.

    – Joel C
    May 30 at 19:14

















-1















From what I have read on packet forwarding, in case of a multihomed host that is connected to two different networks, packet forwarding allows packets to travel from one network to another through its two network interfaces.



Given the above, I have a Raspberry Pi setup with its WiFi connected to the Internet via a router. The WiFi interface has an IP address of 10.0.0.10 obtained via DHCP from the router. I have the RPI's Ethernet interface connected to a computer. The Ethernet interface has a static IP address of 192.168.0.1 and the computer obtains an IP address 192.168.0.15 from the DHCP server running on the RPI. The setup looks like this:



Router[10.0.0.1] <--> RPI WiFi[10.0.0.10] <--> RPI Ethernet[192.168.0.1] <--> PC[192.168.0.15]



Going by the definition of packet forwarding for a multihomed host, on applying the following Iptable rules that forwards packets from RPI's Ethernet to WiFi, I expect the computer to be able to ping the router [10.0.0.1] and also connect to the Internet.



iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT
iptables -A FORWARD -i wlan0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT



However, things do not work as I expected. Whereas, on removing the above rules and adding the NAT rule:



iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE



The computer is able to connect to the Internet.



  • Why doesn't the packet forwarding work?

  • Or if it works why can't I ping or get the computer to access the Internet?

  • What would I need to do to have all traffic on the Ethernet interface go out via the WiFi?

Note: I have forwarding enabled on the RPI.










share|improve this question

















  • 1





    You need the masquerade because the router has no idea that the 192.168.0.0/24 network is reachable via the raspberry pi. Masquerade changes the address to that of the pi, which the router knows how to reach (it's the same local network).

    – yoonix
    May 30 at 17:57











  • @yoonix Just to re-phrase, what you are saying is the computer is able to reach the router via forwarding, however, the router itself is not able to respond to the ping or send the requested webpage back to the computer as it cannot reach the 192.168.0.0/24 network? Then a question arises, can we masquerade without NATting? What other options do we have to enable cross communication?

    – John
    May 30 at 18:07











  • @John, you would need to add a route to the router so that it knows that it can reach the 192.168.0.0/24 network via the RPi. The steps for doing that depend greatly on your router model, and may in fact not be possible.

    – Joel C
    May 30 at 19:14













-1












-1








-1








From what I have read on packet forwarding, in case of a multihomed host that is connected to two different networks, packet forwarding allows packets to travel from one network to another through its two network interfaces.



Given the above, I have a Raspberry Pi setup with its WiFi connected to the Internet via a router. The WiFi interface has an IP address of 10.0.0.10 obtained via DHCP from the router. I have the RPI's Ethernet interface connected to a computer. The Ethernet interface has a static IP address of 192.168.0.1 and the computer obtains an IP address 192.168.0.15 from the DHCP server running on the RPI. The setup looks like this:



Router[10.0.0.1] <--> RPI WiFi[10.0.0.10] <--> RPI Ethernet[192.168.0.1] <--> PC[192.168.0.15]



Going by the definition of packet forwarding for a multihomed host, on applying the following Iptable rules that forwards packets from RPI's Ethernet to WiFi, I expect the computer to be able to ping the router [10.0.0.1] and also connect to the Internet.



iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT
iptables -A FORWARD -i wlan0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT



However, things do not work as I expected. Whereas, on removing the above rules and adding the NAT rule:



iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE



The computer is able to connect to the Internet.



  • Why doesn't the packet forwarding work?

  • Or if it works why can't I ping or get the computer to access the Internet?

  • What would I need to do to have all traffic on the Ethernet interface go out via the WiFi?

Note: I have forwarding enabled on the RPI.










share|improve this question














From what I have read on packet forwarding, in case of a multihomed host that is connected to two different networks, packet forwarding allows packets to travel from one network to another through its two network interfaces.



Given the above, I have a Raspberry Pi setup with its WiFi connected to the Internet via a router. The WiFi interface has an IP address of 10.0.0.10 obtained via DHCP from the router. I have the RPI's Ethernet interface connected to a computer. The Ethernet interface has a static IP address of 192.168.0.1 and the computer obtains an IP address 192.168.0.15 from the DHCP server running on the RPI. The setup looks like this:



Router[10.0.0.1] <--> RPI WiFi[10.0.0.10] <--> RPI Ethernet[192.168.0.1] <--> PC[192.168.0.15]



Going by the definition of packet forwarding for a multihomed host, on applying the following Iptable rules that forwards packets from RPI's Ethernet to WiFi, I expect the computer to be able to ping the router [10.0.0.1] and also connect to the Internet.



iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT
iptables -A FORWARD -i wlan0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT



However, things do not work as I expected. Whereas, on removing the above rules and adding the NAT rule:



iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE



The computer is able to connect to the Internet.



  • Why doesn't the packet forwarding work?

  • Or if it works why can't I ping or get the computer to access the Internet?

  • What would I need to do to have all traffic on the Ethernet interface go out via the WiFi?

Note: I have forwarding enabled on the RPI.







iptables nat forwarding raspbian






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked May 30 at 17:54









JohnJohn

99




99







  • 1





    You need the masquerade because the router has no idea that the 192.168.0.0/24 network is reachable via the raspberry pi. Masquerade changes the address to that of the pi, which the router knows how to reach (it's the same local network).

    – yoonix
    May 30 at 17:57











  • @yoonix Just to re-phrase, what you are saying is the computer is able to reach the router via forwarding, however, the router itself is not able to respond to the ping or send the requested webpage back to the computer as it cannot reach the 192.168.0.0/24 network? Then a question arises, can we masquerade without NATting? What other options do we have to enable cross communication?

    – John
    May 30 at 18:07











  • @John, you would need to add a route to the router so that it knows that it can reach the 192.168.0.0/24 network via the RPi. The steps for doing that depend greatly on your router model, and may in fact not be possible.

    – Joel C
    May 30 at 19:14












  • 1





    You need the masquerade because the router has no idea that the 192.168.0.0/24 network is reachable via the raspberry pi. Masquerade changes the address to that of the pi, which the router knows how to reach (it's the same local network).

    – yoonix
    May 30 at 17:57











  • @yoonix Just to re-phrase, what you are saying is the computer is able to reach the router via forwarding, however, the router itself is not able to respond to the ping or send the requested webpage back to the computer as it cannot reach the 192.168.0.0/24 network? Then a question arises, can we masquerade without NATting? What other options do we have to enable cross communication?

    – John
    May 30 at 18:07











  • @John, you would need to add a route to the router so that it knows that it can reach the 192.168.0.0/24 network via the RPi. The steps for doing that depend greatly on your router model, and may in fact not be possible.

    – Joel C
    May 30 at 19:14







1




1





You need the masquerade because the router has no idea that the 192.168.0.0/24 network is reachable via the raspberry pi. Masquerade changes the address to that of the pi, which the router knows how to reach (it's the same local network).

– yoonix
May 30 at 17:57





You need the masquerade because the router has no idea that the 192.168.0.0/24 network is reachable via the raspberry pi. Masquerade changes the address to that of the pi, which the router knows how to reach (it's the same local network).

– yoonix
May 30 at 17:57













@yoonix Just to re-phrase, what you are saying is the computer is able to reach the router via forwarding, however, the router itself is not able to respond to the ping or send the requested webpage back to the computer as it cannot reach the 192.168.0.0/24 network? Then a question arises, can we masquerade without NATting? What other options do we have to enable cross communication?

– John
May 30 at 18:07





@yoonix Just to re-phrase, what you are saying is the computer is able to reach the router via forwarding, however, the router itself is not able to respond to the ping or send the requested webpage back to the computer as it cannot reach the 192.168.0.0/24 network? Then a question arises, can we masquerade without NATting? What other options do we have to enable cross communication?

– John
May 30 at 18:07













@John, you would need to add a route to the router so that it knows that it can reach the 192.168.0.0/24 network via the RPi. The steps for doing that depend greatly on your router model, and may in fact not be possible.

– Joel C
May 30 at 19:14





@John, you would need to add a route to the router so that it knows that it can reach the 192.168.0.0/24 network via the RPi. The steps for doing that depend greatly on your router model, and may in fact not be possible.

– Joel C
May 30 at 19:14










0






active

oldest

votes












Your Answer








StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f969539%2fiptables-packet-forwarding-vs-nat%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes















draft saved

draft discarded
















































Thanks for contributing an answer to Server Fault!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f969539%2fiptables-packet-forwarding-vs-nat%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020