Re: NAT or Proxy?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, Jun 13, 2003 at 11:31:54AM +1000, George Vieira wrote:

> Change your ACCEPT to MAQUERADE.. ACCEPT will cause your 192.168.0.0 IPs to go out to the internet and guess what the ISP does to them.. yes, drops them...

Actually the ISP's don't bother to check the source and drop if private IP
found. They just route it to their destination. It's the return packets
which would get dropped because of the lack of the routing entry...

I know, they should check the src not only for the private IP's but also
for the spoofed packets but just imagine the load of this process on the
edge routers...

Ramin

> Thanks,


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux