Hello, Italo Valcy a écrit : > > I'm in doubt about the correct use of DNAT, if I should use an alias > interface (like eth0:0) with the original target IP address Target ? Do you mean the original destination address ? > or I should > use something to advertise the arp-reply for that IP (like farpd). As long as incoming packets reach the interface, it does not matter how. > I'm asking this because when I tried to use the alias interface I've got > *some* packages being processed by INPUT chain of the filter table... Please provide some details about the rule, packets... Note that iptables' NAT ignores packets in the INVALID state. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html