On Tuesday 2009-10-20 10:16, Daniel Huhardeaux wrote: > > I'm running few virtual machines (kvm+libvirt) on a server (Debian Lenny + > backport kernel 2.6.30) with one public IP and having IP private range > 10.99.0.1 for host, one for mail and web VM (10.99.0.13), another for telephony > VM (10.99.0.11). > > Everything is working well (DNAT) but something is disturbing me: for instance, > on smtp server, all incoming tcp packets are marked with 10.99.0.1 source IP > and I would like to have "transparent DNAT" which keep the original IP. You need tproxy then, and not NAT. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html