From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kiran Kumar Immidi Subject: Re: NAT question Date: Wed, 30 Jun 2004 07:28:29 -0600 (MDT) Sender: netfilter-devel-admin@lists.netfilter.org Message-ID: <20040630132829.9B5144C0DC@spy10.spymac.net> Reply-To: immidi@spymac.com Mime-Version: 1.0 Content-Type: text/html; Content-Transfer-Encoding: quoted-printable Return-path: Content-Disposition: inline To: immidi@spymac.com, netfilter-devel@lists.netfilter.org, Vijaya Chandra Vupputuri Errors-To: netfilter-devel-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Unsubscribe: , List-Archive: List-Id: netfilter-devel.vger.kernel.org

Regards,
Kiran Kumar Immidi

On Wed, 30 Jun 2004 17:56 , Vijaya Chandra Vupputuri <vijay@tachyon= tech.net> sent:

>If A and B send packets to a server, say google.com:80 using the = local
>port 10000, when the pkts get SNATed on C, the source ports would be<= BR> >different from 10000 (21000 and 32000 for example) and when google.co= m
>sends back the packets to those new port numbers, conntrack would cha= nge
>the dst-port numbers to 10000 along with the dst-ip address.

  Oh yes, this answers my question. But how about ICMP which does no= t have a concept of port?
I have asked this in another mail.


Cool Things Happen When Mac Users Meet! Join the community in Bos= ton this July: www.macworldexpo.com