Re: ip6tables REDIRECT support

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 9/28/2012 10:22 PM, Steve (Telsat Broadband) wrote:
Hi Eliezer,

We use our own custom server.  The server listens for connections on all
ports for both TCP & UDP and forwards any unauthenticated connections to two
separate services running on the same machine.  The problem with TPROXY was
that despite it being configured exactly as we've configured it in the past
when we used a squid proxy, the data packets never hit the services on the
server which were supposed to handle them.

So I ask, Why if it worked with squid it's not working with your server?
the only answer I can think of is that you didn't used the right configurations on the server to work with tproxy.
it requires special socket options that are not similar to any regular ones.

Works for me with tproxy and does what I need.

Eliezer
The redirect target worked perfectly for this situation, simply capturing
any packets on dport 1-65535 and redirecting it to port xxx on the same
machine.  Simply shifting port X to port Y without any other modifications.

Cheers.
Steve.


Steve Noorderbroek
C.T.O.
Telsat Broadband Limited
www.telsatbb.vu
<SNIP>
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux