IPTABLES MASQUERADE - WAN is OK but no LAN traffic...



Here is the masquerade section of rules that I have set up...

iptables -t nat -A POSTROUTING -s 172.19.0.0/24 -j SNAT --to
66.119.9.186
iptables -A FORWARD -t filter -m state --state NEW,ESTABLISHED,RELATED
-j ACCEP
iptables -A FORWARD -t filter -m state --state ESTABLISHED,RELATED -j
ACCEPT


1. If I set an IP on the 66.119.9.0/24 network, Everything is OK.
2. When I set up IP: 172.19.0.2 SM: 255.255.255.0 GW:172.19.0.1 I can
get traffic out of the network just fine but can no longer access the
66.119.9.0/24 network.
3. I can ping google via it's IP and Yahoo via the IP but not my
servers on the 66.119.9.0/24.
4. I had to use a DNS server that was outside of my network in order to
resolve domains as my DNS is on the 66.119.9.0/24 network.

Can someone tell me what the heck I'm doing wrong?

.



Relevant Pages

  • RE: IPS comparison
    ... >It might if your DNS server doesn't normally do this. ... and anomaly detection. ... analysis tool for network traffic, netflow, firewall logs, host logs, .etc, ... but anomaly detection is just that -- anomalies. ...
    (Focus-IDS)
  • RE: DC Issues
    ... DCs are imputable to DNS server problems. ... For your replication, you should be aware that you will be needing two ... maintain the DCs connected in this network updated. ... Server is not responding or is not considered suitable. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How is DNS resolution working?
    ... >> and our DNS server on machine B is only on a private network, ... host on the external network ... It just happens that on the external network, there is a Windows domain ...
    (microsoft.public.win2000.networking)
  • Re: Event errors
    ... need of a serious professional overhaul of your network, ... Event Source: NETLOGON ... authoritative DNS server required to process this update request has ...
    (microsoft.public.windowsxp.network_web)
  • Re: How is DNS resolution working?
    ... >> and our DNS server on machine B is only on a private network, ... host on the external network ... It just happens that on the external network, there is a Windows domain ...
    (microsoft.public.win2000.dns)