无需DNS:DD-WRT路由器外部IP转内部IP的iptables配置问询
Let's break down your issue and get this working step by step—first off, I spot a straightforward mistake in your existing command, plus we need to cover a couple of edge cases for full functionality.
First: Correct the DNAT Target IP
Your current rule routes traffic to your router's LAN IP (192.168.0.1) instead of your target debug device (192.168.0.22). Let's delete that incorrect rule first:
iptables -t nat -D PREROUTING -i br0 -d 69.39.239.211 -j DNAT --to 192.168.0.1
Now Configure Rules for Two Scenarios
Traffic can come from two places—external internet or your internal LAN. We need to handle both properly.
1. External Internet Traffic to Your Public IP
DD-WRT uses vlan0 as the default WAN interface (if yours uses eth1 or another name, substitute it here). Add rules to route WAN traffic to your internal device:
# Route incoming WAN traffic targeting 69.39.239.211 to 192.168.0.22 iptables -t nat -A PREROUTING -i vlan0 -d 69.39.239.211 -j DNAT --to-destination 192.168.0.22 # Allow the forwarded traffic through the router's FORWARD chain iptables -A FORWARD -i vlan0 -d 192.168.0.22 -j ACCEPT
2. Internal LAN Traffic to Your Public IP (Hairpin NAT)
If you're testing from a device inside your network (accessing 69.39.239.211 from 192.168.0.x), you need "hairpin NAT" to make return traffic route correctly:
# Route internal traffic targeting your public IP to the internal device iptables -t nat -A PREROUTING -i br0 -d 69.39.239.211 -j DNAT --to-destination 192.168.0.22 # Rewrite source IP so return traffic goes back to the internal device iptables -t nat -A POSTROUTING -o br0 -s 192.168.0.0/24 -d 192.168.0.22 -j SNAT --to-source 192.168.0.1 # Allow this internal forwarded traffic iptables -A FORWARD -i br0 -d 192.168.0.22 -j ACCEPT
Troubleshooting the Nmap Issue
If traceroute works but Nmap can't see open ports, check these two things:
- Target device firewall: Make sure
192.168.0.22allows incoming traffic from your router, and the ports you're testing are open. This is the most common culprit here. - Port-specific rules: If you only need to forward specific ports (e.g., 80, 443), add a
--dportflag to your PREROUTING rule to narrow it down:iptables -t nat -A PREROUTING -i vlan0 -d 69.39.239.211 --dport 80 -j DNAT --to-destination 192.168.0.22:80
You can verify your rules are active with iptables -t nat -L (for NAT chain) and iptables -L (for FORWARD chain).
内容的提问来源于stack exchange,提问作者John Smith

