You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需DNS:DD-WRT路由器外部IP转内部IP的iptables配置问询

Fixing IP Routing/Redirect with DD-WRT iptables

Let's break down your issue and get this working step by step—first off, I spot a straightforward mistake in your existing command, plus we need to cover a couple of edge cases for full functionality.

First: Correct the DNAT Target IP

Your current rule routes traffic to your router's LAN IP (192.168.0.1) instead of your target debug device (192.168.0.22). Let's delete that incorrect rule first:

iptables -t nat -D PREROUTING -i br0 -d 69.39.239.211 -j DNAT --to 192.168.0.1

Now Configure Rules for Two Scenarios

Traffic can come from two places—external internet or your internal LAN. We need to handle both properly.

1. External Internet Traffic to Your Public IP

DD-WRT uses vlan0 as the default WAN interface (if yours uses eth1 or another name, substitute it here). Add rules to route WAN traffic to your internal device:

# Route incoming WAN traffic targeting 69.39.239.211 to 192.168.0.22
iptables -t nat -A PREROUTING -i vlan0 -d 69.39.239.211 -j DNAT --to-destination 192.168.0.22

# Allow the forwarded traffic through the router's FORWARD chain
iptables -A FORWARD -i vlan0 -d 192.168.0.22 -j ACCEPT

2. Internal LAN Traffic to Your Public IP (Hairpin NAT)

If you're testing from a device inside your network (accessing 69.39.239.211 from 192.168.0.x), you need "hairpin NAT" to make return traffic route correctly:

# Route internal traffic targeting your public IP to the internal device
iptables -t nat -A PREROUTING -i br0 -d 69.39.239.211 -j DNAT --to-destination 192.168.0.22

# Rewrite source IP so return traffic goes back to the internal device
iptables -t nat -A POSTROUTING -o br0 -s 192.168.0.0/24 -d 192.168.0.22 -j SNAT --to-source 192.168.0.1

# Allow this internal forwarded traffic
iptables -A FORWARD -i br0 -d 192.168.0.22 -j ACCEPT

Troubleshooting the Nmap Issue

If traceroute works but Nmap can't see open ports, check these two things:

  • Target device firewall: Make sure 192.168.0.22 allows incoming traffic from your router, and the ports you're testing are open. This is the most common culprit here.
  • Port-specific rules: If you only need to forward specific ports (e.g., 80, 443), add a --dport flag to your PREROUTING rule to narrow it down:
    iptables -t nat -A PREROUTING -i vlan0 -d 69.39.239.211 --dport 80 -j DNAT --to-destination 192.168.0.22:80
    

You can verify your rules are active with iptables -t nat -L (for NAT chain) and iptables -L (for FORWARD chain).

内容的提问来源于stack exchange,提问作者John Smith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:46:27