All of lore.kernel.org
 help / color / mirror / Atom feed
From: Internet Protocol version Six <inet6@mail.be>
To: netfilter@newkirk.us
Cc: netfilter@lists.netfilter.org
Subject: Re: IPv6 Router and NAT/connection tracking
Date: Sat, 21 Jun 2003 00:27:17 +0200 (GMT+02:00)	[thread overview]
Message-ID: <1547190167.1056148037625.JavaMail.Administrator@pumbaa> (raw)

Well, I just tried it, still the same, connections from the
routerbox itself to the Internet (like an IRC server) don't timeout,
but connections to the Internet from a machine on the network do
timeout after a 4 minutes or something and traceroutes to the address
of the machine on the network ends at the router, timing out.
And then I cannot establish a connection anymore unless I tracert6
from the networkmachine to a hostname on the Internet, doesn't even
matter which address I traceroute6 too, aslong as it's an Internet
address and then the whole thing works again..., repeating the same
problem again :(

> ----------------------------------------
> From: Joel Newkirk <netfilter@newkirk.us>
> Sent: Fri Jun 20 08:24:48 GMT+02:00 2003
> To: Internet Protocol version Six <inet6@mail.be>
> Subject: Re: IPv6 Router and NAT/connection tracking
> 
> 
> On Wed, 2003-06-18 at 20:09, Internet Protocol version Six wrote:
> > I'm connected via IPv6-in-IPv4 and I have a /48 assigned to this
> > box, and I want the box to act as a router for my machines which
> > it's doing nicely, only the conntrack thing is annoying the hell
> > outta me ;) Will that solve it (ACCEPTING in both directions)?
> > 
> > And so what you are saying is that I should do this?:
> > iptables -I INPUT -p 41 -j ACCEPT
> > iptables -I OUTPUT -p 41 -j ACCEPT
> > iptables -I PREROUTING -p 41 -j ACCEPT -> not sure about this one
> > 
> > or am I wrong/forgetting something? :)
> > 
> > Thanks for your help, greatly appreciated
> 
> AFAIK that is correct.  (however the PREROUTING one wouldn't work, would
> need to be NAT table, and would be unnecessary anyway since that chain
> is supposed to have an ACCEPT policy - NAT in NAT table, filter in
> FILTER table)  The two rules, INPUT and OUTPUT, should overcome any
> failure of the state machine to recognize intermittent tunnel traffic as
> ESTABLISHED.
> 
> Regarding 'internal' ipv6 traffic within your network, I suspect you
> should be using ip6tables there if needed.  (ip6tables won't see 6in4
> tunnel traffic though, since the tunnel itself is IPv4)
> 
> I haven't configured my gateway as an ipv6 router yet, however.  I have
> a single address ATM from freenet6.  When I get the chance to tinker (a
> few weeks from now at least) I want to configure ipv6 on my desktop as
> well as my server and see what there is to see.
> 
> j
> 
> 
> 
> 

-----------------------------------------------------
Mail.be, WebMail and Virtual Office
http://www.mail.be



             reply	other threads:[~2003-06-20 22:27 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-06-20 22:27 Internet Protocol version Six [this message]
  -- strict thread matches above, loose matches on Subject: below --
2003-06-23 16:41 IPv6 Router and NAT/connection tracking Internet Protocol version Six
2003-06-19  0:09 Internet Protocol version Six
2003-06-20  6:24 ` Joel Newkirk
2003-06-18 21:05 Internet Protocol version Six
2003-06-18 22:28 ` Joel Newkirk

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1547190167.1056148037625.JavaMail.Administrator@pumbaa \
    --to=inet6@mail.be \
    --cc=netfilter@lists.netfilter.org \
    --cc=netfilter@newkirk.us \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.