I’m trying to setup ip forwarding without masquarade. In other words, plain gateway.
I have one RED interface and one Green.
Red interface has public ip /30 mask and the Green interface has the same network segment /26 mask
The problem is to make nethserver to disable masquarade on postrouting and to enable forwarding.
In iptables I have this :
Chain PREROUTING (policy ACCEPT 266K packets, 32M bytes)
Chain INPUT (policy ACCEPT 78 packets, 4964 bytes)
Chain OUTPUT (policy ACCEPT 156 packets, 11809 bytes)
Chain POSTROUTING (policy ACCEPT 38 packets, 1747 bytes)
pkts bytes target prot opt in out source destination
186K 26M MASQUERADE all – * ens19 0.0.0.0/0 0.0.0.0/0
And this for FORWARD chain:
-P FORWARD DROP
I tried to make 2nd interface ORANGE, but it did not work. Still masquerading
If I set the 2nd interface RED and manually set iptables -P FORWARD ACCEPT, it works as I wan to.
Though, when I make any change in the firewall via the UI, it pushes it back to -P FORWARD DROP.
Is there a way to achieve ip forwarding without masquerading via the UI ?
NethServer Version: 7.9.2009 (final)