On Thu, 11 Jun 2009 11:42:44 +0800 Tony Wan <visual2me@xxxxxxxxx> wrote: > Hi all, > > It's said that TCP hole punch does not work if both endpoints come > from 2 sub-networks, whose NAT are both implemented by iptables. I > just want to make sure whether this is true. If so, what type of nat > can iptables work as? full-cone, restricted, port restricted, or > symmetric? > > Sorry if it's not appropriate to ask such a question here. Thanks in advance. You might want to look up STUNT which uses an intermediary to open the NAT tunnel. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html