Re: REDIRECTing many ports to one leads to 4-tuple conflicts

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> The privilege requirement could be lifted I think, I guess you want to run this in an unpriv container?

Yes, we have a privileged component that enters the network namespace
of unprivileged containers to setup rules. So we can setup iptables
rules, etc, but in our user space proxy doing things that require
privileges link setting marks or IP_TRANSPARENT won't work.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux