On Fri, Nov 30, 2012 at 11:37:26PM +0100, Jozsef Kadlecsik wrote: > When the route changes (backup default route, VPNs) which affect a > masqueraded target, the packets were sent out with the outdated source > address. The patch addresses the issue by comparing the outgoing interface > directly with the masqueraded interface in the nat table. > > Events are inefficient in this case, because it'd require adding route > events to the network core and then scanning the whole conntrack table > and re-checking the route for all entry. Applied, thanks. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html