Re: conntrack output - question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi,

Le lundi 06 août 2012 à 22:38 -0700, Gomathivinayagam Muthuvinayagam a
écrit :
> Conntrack classifies a packet to a flow based on protocol no, srcip,
> destip, srcport, and destport.
> 
> A sample output is shown below,
> 
> [NEW] udp      17 30 src=192.168.2.100 dst=192.168.2.1 sport=57767
> dport=53 [UNREPLIED] src=192.168.2.1 dst=192.168.2.100 sport=53
> dport=57767
> 
> Here, what's the need of reply srcip, reply destip, reply srcport,
> reply destport? (Since we can imply these information from original
> srcp ip, original destip, original srcport, original destport)
> Is it just for avoiding for confusion, or anyother reasons behind this?

Think about NAT.

BR,
-- 
Eric Leblond 
Blog: http://home.regit.org/ - Portfolio: http://regit.500px.com/

Attachment: signature.asc
Description: This is a digitally signed message part


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux