firewalld icon indicating copy to clipboard operation
firewalld copied to clipboard

Preserve source IP when using masquerade + rich-rule port-forwading

Open crimewaffle opened this issue 1 year ago • 0 comments

What would you like to be added

Not sure if this is already implemented and just a mistake on my end or not.

The ability to preserve the IP of the origin when port-forwading using rich rules.

example: When users have a rule like rule family="ipv4" destination address="EXTERNALIP" forward-port port="80" protocol="tcp" to-port="80" to-addr="INTERNALIP" the service at INTERNALIP only sees the internal (NAT) gateway as a source instead of the "actual" source.

Why is this needed

No response

crimewaffle avatar Jan 30 '24 22:01 crimewaffle