Nishit Shah a écrit :
NAT may implicitly change the original source port in order to
avoid a clash with an existing connection.
Hmm... So if I need original source IP and port in proxy (like
SO_ORIGINAL_DST, something SO_ORIGINAL_SRC) I should trust conntrack not the
socket info, correct ?
I guess so, unless it exists some option similar to SO_ORIGINAL_DST,
which is IMHO a ugly hack.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html