filter before NAT

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi All.

I am trying to control some outbound traffic thru a Linux NATing box via this:

$TC filter add dev $INTERNET protocol ip parent 3: pref 1 \
   u32  \
      match ip src 192.168.106.2  \
   flowid 3:5602

The problem is that the packets are hooked *after* passing SNAT and all the
rules can see is the outbound IP. So no redirects to the corresponding
flowid occur.

Is it possible to make the filter rule above "see" the packets before they
get NATed?

Environment
	Slackware 12.1.0 kernel 2.6.24.5-smp
	

Regards

Ethy
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux