Hi, I think the next link will help you http://forums1.itrc.hp.com/service/forums/bizsupport/questionanswer.do?threadId=1032378&admit=-682735245+1154757766144+28353475 just read threads carefuly. Instead port 80 you can put port 443 as well. Or both. In my case this work. And of course read http://iptables-tutorial.frozentux.net/iptables-tutorial.html best wishes --- notinh notien <notinhnotien7@xxxxxxxxxxx> wrote: > Hi. I am a newbie here, I need some helps for my > situation. > > My set up is that I have Apache as the web server > and set it up so that it > would do proxy reverse to the backend web server. > It is all good and my > user can use the front web server to view the > content provided by the > backend web server. > > So I only open my hardware firewall and forward all > access to the front end > server. My front end server is a Linux box and have > iptables to protect it. > Now i need to forward the ports that are not part > of the Apache reverse > proxy (80, 443) to the backend server. > > So you see, my front end server is not a gateway and > does not provide NAT to > any other server like a firewall gateway settings. > I already have a > hardware firewall to protect these two servers. > These two servers are in > the same subnet 192.168.0.0/24. I only need it to > forward ports to the > backend server and return related data for > connections from the back end on > those ports to outside people. I want people to > have the impression that > they are connecting to the same server because the > software I used do not > allow setting more than one IP address for all the > services from the end > user GUI. > > Could someone here show me how to do this? Should > NAT involve in this? > > Thanks. > > _________________________________________________________________ > Express yourself instantly with MSN Messenger! > Download today it's FREE! > http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/ > > > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com