All of lore.kernel.org
 help / color / mirror / Atom feed
* Try to NAT a RTP stream
@ 2003-04-27  6:24 Nils Ohlmeier
  2003-04-30  3:26 ` Tom Marshall
  0 siblings, 1 reply; 6+ messages in thread
From: Nils Ohlmeier @ 2003-04-27  6:24 UTC (permalink / raw)
  To: netfilter

Hello,

i try to NAT RTP streams with my own application (i do not use iptables to 
insert the rules -> should i go to netfilter-devel?).

Scenario:
192.168.0.114 <-----> 192.168.0.2
                      Netfilter NAT
                     217.224.223.167 <--------------> 195.37.77.110

The result is that packets go from private to public but not vice versa. And 
the ruleset looks like this (empty chains omitted, ruleset is only for 
debuging, masquerade rule is for keeping my existing connections):

Chain FORWARD (policy ACCEPT 237 packets, 47356 bytes)
 pkts bytes target     prot opt in     out     source               
destination
    0     0 ACCEPT     udp  --  *      *       195.37.77.110        
192.168.0.114      udp spts:18554:18555 dpts:8766:8767
  399 79648 ACCEPT     udp  --  *      *       192.168.0.114        
195.37.77.110      udp spts:8766:8767 dpts:18554:18555

Chain PREROUTING (policy ACCEPT 3481 packets, 552K bytes)
 pkts bytes target     prot opt in     out     source               
destination
    0     0 DNAT       udp  --  *      *       195.37.77.110        
217.224.223.167    udp spts:18554:18555 dpts:32790:32791 
to:192.168.0.114:8766-8767

Chain POSTROUTING (policy ACCEPT 660 packets, 52480 bytes)
 pkts bytes target     prot opt in     out     source               
destination
    0     0 SNAT       udp  --  *      *       192.168.0.114        
195.37.77.110      udp spts:8766:8767 dpts:18554:18555 
to:217.224.223.167:32790-32791
    9  1835 MASQUERADE  all  --  *      *       192.168.0.0/23       0.0.0.0/0

What i do not understand is why the packets from internal hit the rule in 
FORWARD but do not hit the same rule in POSTROUTING.
The second strange thing is that packets come in on the external interface 
(observed with ngrep) but to not hit the PREROUTING rule.
I fear i missed something obvious :-(

Any help/ideas appreciated.

Greetings
  Nils Ohlmeier


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-05-02  6:55 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-04-27  6:24 Try to NAT a RTP stream Nils Ohlmeier
2003-04-30  3:26 ` Tom Marshall
2003-04-30 11:12   ` Michael J. Tubby B.Sc. (Hons) G8TIC
2003-04-30 14:28     ` Tom Marshall
2003-05-01  9:17       ` Michael J. Tubby B.Sc. (Hons) G8TIC
2003-05-02  6:55         ` IP-tables with authentication Yogesh Talekar (M.T.S.@C.N.C.)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.