So i’ve got a customer who’s got some servers hosted behind a NAT and ports forwarded to it. He’s also got two WAN links. We’ll call them WAN1 and WAN2. I need to do some policy-based routing over WAN1 which just so happens to be the WAN link that the dst-nat rules are on.
Here’s what I set up:
- Routing mark on for default route on WAN1
- Route to private IPs within WAN1’s routing table
- mangle prerouting rule to mark outbound port 25 traffic with WAN1 mark
- mangle prerouting rule to mark all inbound traffic with WAN1 mark
No matter how I try, I cannot get the servers to remain accessible from the outside. What is the typical mangle strategy for making this work?