CREATE NAT TO SAME PORT ON DIFFERENT SERVERS



  • Hi, i need help in a configuration i dont know how make this but the problem is this i have a antispam server (192.168.1.2) your ip public is 190.89.21.11 and have ssh port (22/tcp); also i have a mail server (192.168.1.3) your ip public is 190.89.21.12 and have the same ssh port (22/tcp), what is the rule that can allow conect two different server with the same port or only can change the port of one they



  • @klausneil said in CREATE NAT TO SAME PORT ON DIFFERENT SERVERS:

    190.89.21.1a

    should be a WAN interface "A" with its port 22 NAT rule to "192.168.1.2", port "22".
    190.89.21.1b should be another WAN interface "B" with its port 22 NAT rule to "192.168.1.3", port "22".

    This means that when you remotely connect to 190.89.21.1a on port 22, you wind up connecting to local server 192.168.1.2 - port 22.2.
    Same thing for WAN IP 190.89.21.1b - local server 192.168.1.3.

    The ports may be the same, but source and destination IP's are different, so two NAT rules will work.



  • Hi @Gertjan thanks for you response but i have a one interface WAN with serveral ip alias on this, also the second interface is for the LAN; how can make this NAT on this scenario



  • Ah ...

    From what I make of it, NAT rules are Interface based.

    I guess you have to change one 'outside' port number, like :
    Remotely connect to 190.89.21.1a on port 23, you wind up connecting to local server 192.168.1.2 - port 22.2


  • LAYER 8 Rebel Alliance

    Just pick your IP Alias (Virtual IP) in the NAT Rule.

    -Rico



  • @klausneil said in CREATE NAT TO SAME PORT ON DIFFERENT SERVERS:

    Hi, i need help in a configuration i dont know how make this but the problem is this i have a antispam server (192.168.1.2) your ip public is 190.89.21.11 and have ssh port (22/tcp); also i have a mail server (192.168.1.3) your ip public is 190.89.21.12 and have the same ssh port (22/tcp), what is the rule that can allow conect two different server with the same port or only can change the port of one they

    Yes i already did that 👆


Log in to reply