Re: SNATed connections show as original ip in /proc/net/tcp

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Alexander Clouter
Date: Sunday, July 11, 2010 - 7:30 am

Noah McNallie <n0ah@n0ah.org> wrote:
Probably better to post this to netdev?

SNAT'ing locally sourced traffic?  That's pretty nasty.

Look into using 'ip rule' and a second routing table.

http://lartc.org/howto/lartc.rpdb.html

You will still need use iptables/MARK to do L4 (tcp/udp/etc) policy 
routing though, however now you can dump the ugly SNATing.

Cheers

-- 
Alexander Clouter
.sigmonster says: Where do your SOCKS go when you lose them in th' WASHER?

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
SNATed connections show as original ip in /proc/net/tcp, Noah McNallie, (Sun Jul 11, 2:10 am)
Re: SNATed connections show as original ip in /proc/net/tcp, Alexander Clouter, (Sun Jul 11, 7:30 am)
Re: SNATed connections show as original ip in /proc/net/tcp, Alexander Clouter, (Sun Jul 11, 10:08 am)