Wakko Warner wrote:
Is it possible to use the recent match and dnat to dynamically forward incoming packets destined for a specific port (ident in this case) to the machine that initiated the connection? Or is anything like this possible at all?
There may very well be a way to do it, but if there is, I can't seem to find it, and I know of at least one other person who's messed with it. Best I can tell, midentd on the gateway is going to be your best option. You might find this useful as well - I wrote it up quite some time ago, but coupled with midentd, I think you'll have a workable solution.
http://howtos.rlworkman.net/irc-identd RW