Re: [MASQUERADE] Not changing to new source ip address when dynamically assigned in ppp link

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Jan,

Thanks for your quick reply.

Unfortunately we cannot upgrade our kernels. 

I would like to know if there is any clean work around to deal with this issue.

We do not want to do an iptables restart or server restart to take this effect. 
Also i saw in one of the posts i can set the ip_conntrack_udp_timeout and ip_conntrack_udp_timeout_stream to 0 and revert back after 10 seconds. Since i am a newbie, i am not sure whether this would affect any other application. Is it the best way to deal with this issue?

To understand this problem:-
The ip_dynaddr says it would update the ip address when the packet is retransmitted before we get any incoming packets from the destination.

Since we are using this only for udp, The packets would not be retransmitted.. Is it because of this?

It would be great if you can let us know any clean work around.

Thanks in advance..



----- Original Message -----
From: Jan Engelhardt <jengelh@xxxxxxxxxx>
To: Autocad Learner <learn.autocad@xxxxxxxxx>
Cc: "netfilter@xxxxxxxxxxxxxxx" <netfilter@xxxxxxxxxxxxxxx>
Sent: Monday, July 18, 2011 11:49 AM
Subject: Re: [MASQUERADE] Not changing to new source ip address when dynamically assigned in ppp link

On Monday 2011-07-18 11:39, Autocad Learner wrote:

>We are using linux Red Hat version RHEL 2.6.9-5.EL  and iptables 
>version 1.2.11-3.1.RHEL4 as Source System. The source ip address is 
>assigned dynamically via ppp link over eth0 interface. 
>
>When the link goes down and comes back, we get a new ip address and it 
>is evident in the ppp0 interface. But the packets going out of our 
>system still uses the old ip address.

This is already fixed in contemporary kernels AFAICS.

--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux