Re: Problem setting up nftables dnat : dport set to 0 instead of requested value (22)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




Le 11/12/2014 14:12, leroy christophe a écrit :

Le 10/12/2014 19:22, Pablo Neira Ayuso a écrit :
On Wed, Dec 10, 2014 at 03:39:04PM +0100, leroy christophe wrote:
Hi,

I'm trying to redirect incoming tcp connections for port 222 to
local port 22 (because I will dnat incoming connections for port 22
to another destination).
Then you have to use "redirect" instead of "dnat". "redirect" will be
available since the upcoming 3.19-rc.

Cc'ing Arturo, he has worked on the redirect support.

@Arturo: Could you add documentation for your 'redirect' support to ?

http://wiki.nftables.org/wiki-nftables/index.php/Performing_Network_Address_Translation_%28NAT%29

Thanks.

Thanks for the information.

I have now applied patches 8d13edd, 9de920e and e9105f1 on my 3.18 kernel, so now the redirect rule is accepted, but I still get the same issue: dport gets value 0 instead of 22 after the redirect, see below

Is there any other patch to apply ?

Christophe

Issue identified. I'll write another mail to explain it.

Christophe

[ 932.304106] redir IN=eth0 OUT= MAC=08:00:51:20:44:5b:08:00:27:fe:42:1e:08:00 SRC=172.25.231.37 DST=172.25.231.5 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=22863 DF PROTO=TCP SPT=55116 DPT=222 WINDOW=14600 RES=0x00 SYN URGP=0 [ 932.304523] rejected IN=eth0 OUT= MAC=08:00:51:20:44:5b:08:00:27:fe:42:1e:08:00 SRC=172.25.231.37 DST=172.25.231.5 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=22863 DF PROTO=TCP SPT=55116 DPT=0 WINDOW=14600 RES=0x00 SYN URGP=0


--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux