[Firewall] Remapping local ports

Arno van Amersfoort arnova at rocky.eld.leidenuniv.nl
Mon Jul 28 07:02:50 MDT 2008

This should be possible I guess..... You're maybe even able to "abuse" 
the NAT forward stuff for it, by simply specifying localhost with a 
different port as target host....


Philip Prindeville wrote:
> I was wondering what would be involved in doing the following:
> I want to take a port (X) and relocate it to another (X') and block X 
> externally, but allow X'.
> Can we do something like:
> ...
> block port X on external interface
> if a packet comes in on port X', jump to another chain (EXT_REMAP)
> accept port X
> ...
> dnat port X' to port X
> return
> In other words, we won't allow connections directly to X to come in from 
> the outside, but we will allow connections to a service running locally 
> that is point to port X to be connected to on a remapped port...
> -Philip
