On Thu, 13 Oct 2005, George Alexandru Dragoi wrote:
application level (if you need them), even it can be tracked very well in FORWARD chains. Else ... who knows, maybe you can do tricks with iproute2 and MARK target from iptables, and instead of nat-ing, you will do some ugly routing. I can't tell exactly how to do this because i didn't read and understand all aspects of your situation.
That might work as well, at least as long as there is no MTU issues or fragmented packets...
Regards Henrik