Re: iptables port redirect question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, 17 Sep 2012 08:12:23 +0200
Michal Kubeček <mkubecek@xxxxxxx> wrote:

> On Monday 17 of September 2012 11:03EN, joydeep@xxxxxxxxxxxxxxx wrote:
> > Hello,
> > 
> > How can I redirect all packets exclude the packets for lan (
> > 192.168.0.0 ) and all packets to/from lo (localhost) ?
> ...
> > But this also redirect all local lan packets naturally, as it compares
> > with lo . How can I combined both lo and local lan ? Can a customized
> > chain help ?
> 
> Yes, in general, custom chain and RETURN target can help to simulate 
> "or" operator. But in your case, you should be able to combine "! -o lo" 
> and "! -d 192.168.0.0/16" matches to do what you need.
> 
> On the other hand, I prefer to explicitly state what I want to 
> masquerade rather than masqeurading everything with some exceptions.
> 
>                                                           Michal Kubeček
> 

Thanks,

Actually my requirement is fulfilled by routing everything excluding lo and
local lan. May be I need to exclude the gmail smtp and pop. But that's all.
Does the "and" operator simply works as you have described ? What should be done
if I go for a custom chain ?

-- regards
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux