Re: CONNMARK udp comprehension question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Peter Warasin wrote:

Now, the question:
I mark all connections entering a specific uplink with a number using
CONNMARK, in order to be able to distinguish them and make them leave
the correct interface using fwmark based ip rules.

You have to restore the mark in your ruleset. Also, UDP has quite a short timeout, so the new packet may not belong to the connection anymore,

HTH,
M4

-
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux