Re: Iproute2 and fwmark usage

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sunday 11 January 2004 8:57 pm, Thhoep wrote:

> in my opinion something is completely wrong with my 2.4.23 kernel. i just
> used another server of mine to reproduce the same situation. for this
> purpose i compiled a completely new 2.4.23 kernel with advanced routing and
> netfilter and whatever support and installed fresh versions of the iptables
> and iproute2 package with the debian system (using 'stable').

What version of iptables is that?   Is it as up to date as the netfilter 
version you've got in your shiny new kernel?

> because the host only has 1 ethernet interface i used a ppp-over-ssh tunnel
> to simulate routing behaviour.

This sounds a little bit dodgy to me....

> then i added a firewall rule
> "iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE"
>
> is anything wrong with it??

No, looks perfectly reasonable to me.

> well do make it short: it changed nothing. packets still get un-masqueraded
> out of ppp0 with local lan ips.

Any chance you can put in another ethernet card and try a simpler routing 
setup?

Antony.

-- 
You can spend the whole of your life trying to be popular,
but at the end of the day the size of the crowd at your funeral
will be largely dictated by the weather.

 - Frank Skinner

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux