Re: Returning nat packets vanishing after mangle:PREROUTING and conntrack processing

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, 19 Dec 2009 14:12:29 +0100, Pascal Hambourg
<pascal.mail@xxxxxxxxxxxxxxx> wrote:
> 
> It may be a source validation issue, which is common in multihomed
> setups. If sysctl net.ipv4.conf.<input_interface>.rp_filter is set to 1,
> does setting it to 0 fix the problem ?
> 

Fantastic, works great.  Changed to 'net.ipv4.conf.default.rp_filter = 0'
in sysctl.conf (was set to 1).

Oddly, I had rp_filter enabled on the system in kernel 2.6.30 and it
worked.  Has rp_filter changed somehow in the newer kernel (or is it now
working 'correctly'?).

Thanks,
Scott
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux