Question

Send all traffic through single IP

I need to use one of the droplets as a public ip that all backend scripts (on other droplets) connect through so the client can open one ip on their firewall but I can farm out the work to various servers.

droplet1/public IP droplet 2 connects private->droplet1->outbound to internet.

Is this possible and or easy to do in any way? Basically share a single outbound IP


Submit an answer

This textbox defaults to using Markdown to format your answer.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

Sign In or Sign Up to Answer

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

Want to learn more? Join the DigitalOcean Community!

Join our DigitalOcean community of over a million developers for free! Get help and share knowledge in Q&A, subscribe to topics of interest, and get courses and tools that will help you grow as a developer and scale your project or business.

You will need to route traffic through the IP you want to see as external, then perform NAT on that droplet.

It’d be much easier to ask the company to have the common sense of whitelisting the IPs you give them instead of forcing you to rework your entire network on their whim.

EDIT: There are obviously other ways to accomplish this, but we have no details about what you’re trying to do. A proxy could maybe work, for instance.

Without know more about your actual use case, it’s hard to get more specific. Here are some tutorials that should point you in the right direction. These show you how to set up private networking and isolate a server:

How To Set Up And Use DigitalOcean Private Networking

How To Isolate Servers Within A Private Network Using IPTables

After that, it really depends on how you need the servers to communicate. If you simply want to pass HTTP requests onto the droplet on the private network, you might want to look into using Nginx as a simple “load balancer.”

If you want to direct all traffic through the one machine, set it allow ip.forwarding and then set routes on them to use the one server as the gateway for certain destinations. You will have to adjust firewalls to match.