From: "Timothy Hayes" <morphieus@earthlink.net>
To: "'\"Oleg A. Arkhangelsky\"'" <sysoleg@yandex.ru>,
'Jan Engelhardt' <jengelh@medozas.de>,
netfilter@vger.kernel.org
Subject: RE: snat range not cycling
Date: Tue, 3 Aug 2010 23:42:33 -0700 [thread overview]
Message-ID: <005601cb33a0$38670290$a93507b0$@net> (raw)
In-Reply-To: <167431280900621@web47.yandex.ru>
Thanks I'll give that a try.
Wouldn't it trying to keep 1 to 1 mapping make the SAME target attribute
redundant?
-----Original Message-----
From: netfilter-owner@vger.kernel.org
[mailto:netfilter-owner@vger.kernel.org] On Behalf Of "Oleg A. Arkhangelsky"
Sent: Tuesday, August 03, 2010 10:44 PM
To: Jan Engelhardt; netfilter@vger.kernel.org
Subject: Re: snat range not cycling
04.08.2010, 02:09, "Jan Engelhardt" <jengelh@medozas.de>:
> IIRC the algorithm tries to give you the same source address for a given
> source address. (I hear that banking sites and other sensitive stuff can
> get unhappy if your externally visible address suddenly changes.)
>
Only when --persist option is given. Otherwise original source and
destination
addresses will be used for selection IP-address from the pool.
Timothy should try connection from different source IP-address or use
different
destination and see how this change situation.
--
wbr, Oleg.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
next prev parent reply other threads:[~2010-08-04 6:42 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-08-03 15:17 [ANNOUNCE]: Release of iptables-1.4.9 Patrick McHardy
2010-08-03 16:34 ` Gabor Z. Papp
2010-08-03 16:34 ` Gabor Z. Papp
2010-08-03 17:05 ` Patrick McHardy
2010-08-03 17:16 ` Gabor Z. Papp
2010-08-03 17:16 ` Gabor Z. Papp
2010-08-03 17:25 ` Gabor Z. Papp
2010-08-03 17:25 ` Gabor Z. Papp
2010-08-03 18:04 ` Jan Engelhardt
2010-08-03 18:09 ` Gabor Z. Papp
2010-08-03 18:09 ` Gabor Z. Papp
2010-08-03 18:34 ` Jan Engelhardt
2010-08-04 17:23 ` Gabor Z. Papp
2010-08-04 17:23 ` Gabor Z. Papp
2010-08-03 22:06 ` snat range not cycling Timothy Hayes
2010-08-03 22:09 ` Jan Engelhardt
2010-08-04 5:43 ` "Oleg A. Arkhangelsky"
2010-08-04 6:42 ` Timothy Hayes [this message]
2010-08-04 6:52 ` "Oleg A. Arkhangelsky"
2010-08-04 8:00 ` Jan Engelhardt
2010-08-04 16:16 ` [ANNOUNCE]: Release of iptables-1.4.9 Patrick McHardy
2010-08-04 16:32 ` Jan Engelhardt
2010-08-06 13:15 ` Patrick McHardy
2010-08-03 17:29 ` Michele Petrazzo - Unipex
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='005601cb33a0$38670290$a93507b0$@net' \
--to=morphieus@earthlink.net \
--cc=jengelh@medozas.de \
--cc=netfilter@vger.kernel.org \
--cc=sysoleg@yandex.ru \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.