Lacking CONNMARK in PREROUTING, some of your SYN/ACK packets may be DROPed by ISPs.
From kernel 2.6.10, CONNMARK is included already, you don't have to patch anything.
Sureerat P. (EQHO) wrote:
Hi all,
Thank you for your kindly reply.
So my next step should be as following:
1. patch the kernel with patch-o-matic 2. add more config with iptables+connmark as described in http://selab.edu.ms/twiki/bin/view/Networking/MultihomedLinuxNetworking
Please you help me suggest whether my understanding is correct. Thank you.
Best regards,
Sureerat P.
_______________________________________________ LARTC mailing list / LARTC@xxxxxxxxxxxxxxx http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/