Re: MASQUERADE: Route sent us somewhere else

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, 2005-01-11 at 08:48, HorvÃth Szabolcs wrote:
> Hello!
> 
> We have a firewall, and it's inside many UML's.
> I can't establish new connections from UML, kernel log says
> "MASQUERADE: Route sent us somewhere else".

this is basically a known issue with policy routing + MASQUERADE.

possible work-arounds:

- use SNAT instead of MASQ (if you have static IPs you should be doing
this anyway)
- use ROUTE to force the --oif (messy)

try an untested patch:

http://marc.theaimsgroup.com/?l=netfilter-devel&m=109866543308978&w=2

please refer to the following thread from netfilter-devel for more
details:

http://marc.theaimsgroup.com/?t=109389731400005&r=2&w=2


--
"Okay, retrace your steps. Woke up, fought with Marge, ate Guatemalan
 insanity peppers, then I... Oh..."
	--The Simpsons




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux