All of lore.kernel.org
 help / color / mirror / Atom feed
* Nat OUTPUT chain
@ 2002-06-15 23:57 hard__ware
  2002-06-15 23:59 ` Antony Stone
  0 siblings, 1 reply; 6+ messages in thread
From: hard__ware @ 2002-06-15 23:57 UTC (permalink / raw)
  To: netfilter

this question is a bit old

but ive seen it asked many other places .. :D


the  -t nat OUTPUT  table seems to work fine for me

i have set up DNAT aswell as ACCEPT Rules

(as i have a Default Policy of DROP,  IPTABLES -P -t  nat OUTPUT DROP  )

and the packets Traverse Through the chain correctly .. :-)

i use two differnet versions of IPTables (i have 2 Firewall Boxes .. :-)

IPTables 1.2.5mdk-1
&
IPTables 1.2.6a

if your having problems with this chain try an upgrade if your not already
at these versions .. :-)


^ permalink raw reply	[flat|nested] 6+ messages in thread
* Nat OUTPUT chain
@ 2002-06-16  2:30 Hard__warE
  0 siblings, 0 replies; 6+ messages in thread
From: Hard__warE @ 2002-06-16  2:30 UTC (permalink / raw)
  To: netfilter

>Why do you DROP in the nat table instead of the filter table ?
>
>
>Antony.

Good Question ...

1. im very Young and i luv nat and seeing what it can do.. :-D , would also
eventually like to gain work in Internet Sercurity / Iptbales / Zebra /
Bridged / Gated / iproute2 / ipchains (yay) / TC  TBF , CBQ , ect ect .

.2 actually i have every single one Policy's set to DROP for all of the
filter & nat chains.. :-D
is there something wrong with that, ?  Yer but you have to check the logs
alot from the Drop & Log end of chain
per chain Rules i have (they all have a different prefix applies ie "Nat
Ouput")
so you can add more rules ...  {:?/]

P.s. and about the MIRROR converstation

i need to set a way so all data on a Given Proto / IP gets MIRRORed but some
how Dnat it
so it goes to a Honney Pot for Logging and decide to take Action or not ..
:-D

(this is nearlly all working except the fact that the Packet / Traffic
accounting is not being properly matched ?? )







^ permalink raw reply	[flat|nested] 6+ messages in thread
* Nat OUTPUT chain
@ 2002-06-02 13:42 gvt_lnx
  2002-06-02 14:05 ` Antony Stone
  0 siblings, 1 reply; 6+ messages in thread
From: gvt_lnx @ 2002-06-02 13:42 UTC (permalink / raw)
  To: netfilter, netfilter

Hi friends, I'am reading some howto and I found that OUTPUT chain in NAT
table is broken...? that's true?

Could I write a rule like this:

iptables -t nat -A OUTPUT -d x.x.x.x -j DNAT --to-destination y.y.y.y

Thanks in advance.
Geffrey

-- 
GMX - Die Kommunikationsplattform im Internet.
http://www.gmx.net



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2002-06-16  7:43 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-06-15 23:57 Nat OUTPUT chain hard__ware
2002-06-15 23:59 ` Antony Stone
2002-06-16  7:43   ` Patrick Schaaf
  -- strict thread matches above, loose matches on Subject: below --
2002-06-16  2:30 Hard__warE
2002-06-02 13:42 gvt_lnx
2002-06-02 14:05 ` Antony Stone

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.