Re: snat local packets and arp

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Marco Berizzi wrote:
Do the routers send arp queries to the Linux box?

Honestly, I don't know. This is the output running
tcpdump -pnvi eth0 arp

10:54:11.787680 : arp who-has adsl.129 tell adsl.134
10:54:11.788293 : arp reply adsl.129 is-at 00:1b:...
10:54:34.580798 : arp who-has adsl.129 tell adsl.134
10:54:34.581441 : arp reply adsl.129 is-at 00:1b:...
10:55:17.420198 : arp who-has adsl.129 tell adsl.134
10:55:17.420836 : arp reply adsl.129 is-at 00:1b:...
10:56:00.552606 : arp who-has adsl.129 tell adsl.134
10:56:00.553231 : arp reply adsl.129 is-at 00:1b:...

I only see the linux box quering the cisco and not
viceversa. AFAIK the cisco has been configured by
the ISP with very high timeout for the arp cache.

PS: The linux is 2.6.23 with default option except
arp_filter/rp_filter/proxy_arp set to 1 on eth0


Try disabling rp_filter, that should make it behave similar
for both addresses. With rp_filter, the input routing done
by arp.c fails because the mark is different and it doesn't
go to your special routing table, so it doesn't update the
cache from arp queries from that router.
-
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux