Re: fwmark & iptables

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Matt Hakim a écrit :
> 
>> Either select the source address in the application or SNAT/MASQUERADE
>> on ppp0 for IPv4 traffic.
> 
> Tried that. Worked outbound, but inbound I could only LOG the packets
> at mangle PREROUTING (I think),  and then they disappeared. No idea
> why.

Forgot about that, sorry. Make sure sysctl net.ipv4.conf.ppp0.rp_filter
is set to 0 after ppp0 is created, otherwise the packet is discarded at
the input routing decision stage. sysctl net.ipv4.conf.default.rp_filter
contains the value that will be set for any new interface.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux