Re: netfilter resets TCP conversation that was DNATed from the local machine to another

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On June 30, 2003 04:07 pm, Michael wrote:

>
> That's Squid looking up my domain. (Why twice? I don't know.) The OUTPUT
> chain in the nat table is
>
> Chain OUTPUT (policy ACCEPT)
>  target prot opt in out source     destination
>  DNAT   tcp  --  *  *   0.0.0.0/0  1.2.3.5     multiport dports 80,443
> to:192.168.0.8 DNAT   tcp  --  *  *   0.0.0.0/0  1.2.3.6     multiport
> dports 80,443 to:192.168.0.9
>
>

	Please read this page
	
	http://www.netfilter.org/documentation/HOWTO//NAT-HOWTO-3.html

	Why are you DNATting in OUTPUT?
-- 

	Alistair Tonner
	nerdnet.ca
	Senior Systems Analyst - RSS
	
     Any sufficiently advanced technology will have the appearance of magic.
	Lets get magical!


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux