DMZ means iptables

Please advise how to configure DMZ iptables — to forward all ports from the external Internet to a computer on the local network? OS Ubuntu Server 10.04
October 14th 19 at 11:55
2 answers
October 14th 19 at 11:57
The DMZ must be separated from the local network.
That is, it must be a separate subnet.
I usually make the following rules for the DMZ.
1) from the Internet to the server in the DMZ prokidyvaya only the necessary ports.
Sorry did not finish.
2) from the server to the Internet only allow established packets

If you need interaction with the network, also
from the local network to the server only the necessary ports
from DMZ to LAN only established packets - eladio43 commented on October 14th 19 at 12:00
October 14th 19 at 11:59
iptables -A PREROUTING policy -t nat-i $ETH -m state --state NEW-j SNAT --to-destination $IP
where $ETH slavushka the provider side, $the server's IP address. And it's not a DMZ
iptables v1.4.0: Unknown arg '--to-destanation' - eladio43 commented on October 14th 19 at 12:02
Need -j DNAT instead of-j SNAT - nikita.Stracke commented on October 14th 19 at 12:05

