Re: DNAT/SNAT & existing connections

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Jul 15, 2003 at 06:01:15PM +0800, Stephen Bylo wrote:

> Dear list,
> 
> I am looking into the use of a NAT "router" to change
> the destination (or source) IP addresses of packets in
> existing connections.  Maybe it sounds weird why I
> might want to do this, but I need to divert streams to
> other destinations!
> 
> I understand from the iptables docs that only the
> first packet of a connection is examined for NAT
> entries, subsequent packets do not need to be
> processed again.

They do get processed. There is a short circuit to identify these
packets and avoid traversing the whole nat table.

It's not clear to me what you precisely want to do.

Ramin

> I would like all packets to be
> examined OR I would like to be able to "reset" the
> particular entry in the table so that the existing
> connection will be "re-considered" again using the
> NAT.
> 
> Is this possible in some way with iptables?  If not,
> can you point me in the right direction to a solution,
> please?
> 
> Thanx,
> Steve
> 
> __________________________________________________
> Do You Yahoo!?
> Send free SMS from your PC!
> http://sg.sms.yahoo.com


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux