All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jason Opperisano <opie@817west.com>
To: netfilter@lists.netfilter.org
Subject: Re: Bizarre rule requirement
Date: Fri, 31 Dec 2004 15:40:04 -0500	[thread overview]
Message-ID: <20041231204004.GA7810@bender.817west.com> (raw)
In-Reply-To: <41D5B11C.9060303@starnetworks.us>

On Fri, Dec 31, 2004 at 01:05:48PM -0700, Kevin P. Fleming wrote:
> Jason Opperisano wrote:
> 
> >here's a thought:  fix your fscking application.
> 
> A working SIP ALG would be the fix for my fscking application... but so 
> far there isn't one available. What's really happening here is that the 
> far end of the "connection" is being moved to a different IP and port; 
> the local end is notified of that before it happens, but conntrack has 
> no idea it is occurring.

not free, but appears to do what you want:

  http://www.wifi.com.ar/english/voip.html

free, seems current, not sure if it meets your requirements:

  http://siproxd.sourceforge.net/index.php

i just googled for "linux sip firewall" so i assuming you're aware of
them and already ruled them out for one reason or another.

> >  # DNAT all UDP ports to 10.1.1.2 port 4000
> >  iptables -t nat -A PREROUTING -i $EXT_IF -p udp \
> >    -j DNAT --to-destination 10.1.1.2:4000
> >
> >  # accept all udp port 4000 packets to 10.1.1.2
> >  iptables -A FORWARD -i $EXT_IF -p udp -d 10.1.1.2 --dport 4000 \
> >    -j ACCEPT
> 
> Even that won't quite do it; I don't want to accept all destination UDP 
> ports to DNAT to the inside device. I want to accept all _source_ UDP 
> ports (from any IP address) as long as they are addressed to the 
> randomly-assigned outbound UDP port that my inside device got when it 
> sent out the first packet. Yeah, I know, it's screwy and funky.

explain to me how the above rules would not successfully forward the UDP
traffic to your server, because i must be missing something.  whether or
not it's how you would *like to do it* is immaterial.

-j


  reply	other threads:[~2004-12-31 20:40 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-12-31 19:29 Bizarre rule requirement Kevin P. Fleming
2004-12-31 19:54 ` Jason Opperisano
2004-12-31 20:05   ` Kevin P. Fleming
2004-12-31 20:40     ` Jason Opperisano [this message]
2004-12-31 22:43       ` Kevin P. Fleming
2004-12-31 22:51         ` Jason Opperisano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20041231204004.GA7810@bender.817west.com \
    --to=opie@817west.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.