Re: [netfilter] Re: iptables problem (nfcan: addressed to exclusive sender for this address)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Ashley,

On Thu, Nov 03, 2005 at 09:02:58AM -0700, Ashley M. Kirchner told us:
>    And I can't tell the other company to send data to separate IPs 
> either because their system works based on the packet they first receive 
> when the kiosk contacts them.  Which goes back to my point above (about 
> putting the kiosks outside the firewall.)

you say "their" system works based on the packet they first receive
when contacting them. So with multiple IPs, wouldn't it work to let
each kiosk contact the server via its own IP address via SNAT??
E.g. kiosk 1 which is internally 1.2.3.4 gets natted to the public
ip 5.6.7.8, so when it contacts the server it will establish a
connection back to 5.6.7.8 which will in turn be DNATted to 1.2.3.4.
kiosk 2 (1.2.3.5) --> 5.6.7.9
and so on...
I haven't read the whole thread, so it might be that I missed
something :-)

Wouldn't this work??


HTH

Sven

-- 
Linux zion.homelinux.com 2.6.14-rc5-mm1_14 #14 Wed Nov 2 11:36:18 CET 2005 i686 athlon i386 GNU/Linux
 17:19:16 up 1 day,  5:25,  2 users,  load average: 0.38, 0.18, 0.07

Attachment: pgpBN6yMN0Rds.pgp
Description: PGP signature


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux