All of lore.kernel.org
 help / color / mirror / Atom feed
* Re: Resend: MASQUERADE: Route sent us somewhere else.
@ 2005-04-05 10:35 Tim Evans
  2005-04-05 14:50 ` Jason Opperisano
  0 siblings, 1 reply; 7+ messages in thread
From: Tim Evans @ 2005-04-05 10:35 UTC (permalink / raw)
  To: netfilter, opie

Thanks for your reply.

>the error message you refer to in your subject is normally encountered
>when using MASQUERADE in conjunction with policy routing, which normally
>implies multiple ISP connections.

Just one connection.

>i cannot find information referencing any of the above in the details of
>your post; which could be a possible explanation for the silence.

Might it be some sort of conflict between my immediate ISP (Comcast) assigning a 
my firewall a domain name via DHCP and my using my "real" domain name on the 
inside?  Again, however, this problem didn't happen with RHEL 3.

I've also noted that if I run a traceroute to my main domain and let it 
finish--it may take a minute or two, but it eventually connects--other 
connections then work.  Immediate workaround is to insert the traceroute into my 
fetchmail cron job. 
--
Tim Evans, TKEvans.com, Inc.	|    5 Chestnut Court
tkevans@tkevans.com		|    Owings Mills, MD 21117
http://www.tkevans.com/		|    443-394-3864
http://www.come-here.com/News/	|    



^ permalink raw reply	[flat|nested] 7+ messages in thread
* Resend: MASQUERADE: Route sent us somewhere else.
@ 2005-04-04 21:55 Tim Evans
  2005-04-05  4:49 ` Jason Opperisano
  0 siblings, 1 reply; 7+ messages in thread
From: Tim Evans @ 2005-04-04 21:55 UTC (permalink / raw)
  To: netfilter

I'm resending this, as this normally vocal list has been unfortunately silent.

------------- Begin Forwarded Message -------------

X-POP3-Rcpt: tkevans@tkevans.com
Date: Sun, 3 Apr 2005 09:39:28 -0400 (EDT)
From: Tim Evans <tkevans@tkevans.com>
To: netfilter@lists.netfilter.org
Content-MD5: nQ1B8/s75ZlYfpSmzC5wHg==
X-Spam-Score: -2.6 (--)
Subject: MASQUERADE: Route sent us somewhere else.
X-Spam-Checker-Version: SpamAssassin 2.64 (2004-01-11) on osprey.tkevans.com
X-Spam-Level: 
X-Spam-Status: No, hits=0.0 required=5.0 tests=none autolearn=no version=2.64

Since upgrading to RedHat Enterprise Version 4, I've been having goofy routing 
problems and iptables has been logging this message regularly:

Apr  3 04:15:01 kestrel kernel: MASQUERADE: Route sent us somewhere else.

My immediate ISP is Comcast, but my main domain is hosted at another ISP.

By "goofy routing problems," I mean I have trouble accessing my *own domain* at 
my ISP for POP-ing down e-mail and *all* other connections.  There are periods 
of anywhere from a few minutes to an hour or longer where all connections to the 
domain simply time out.  At the same time, I *can* connect to other domains, 
including others that belong to me on the same ISP.

During these incidents, traceroutes to my main domain hang at the very first hop 
(Comcast's first router); if I run a traceroute to any other site in a different 
window at the very same time, it proceeds all the way to its destination 
virtually instantly.

The above error consistently corresponds with a cron job that runs fetchmail to 
POP my e-mail down from the ISP.

I have the following lines in my iptables script that reference masquerading:

/sbin/modprobe ipt_MASQUERADE
/sbin/iptables -t nat -A POSTROUTING -o $INET_IFACE -j MASQUERADE

I have not changed the iptables script since upgrading to RHEL 4; I did not see 
any such problems with RHEL 3.

What's doubly goofy about these problems is they're intermittent.  After a spell 
of being unable to connect (again, ranging from just a few minutes to an hour or 
more), it'll suddenly begin working.

And, to repeat, this only affects my primary domain; no other connections to any 
other domain I try see these failures. 
--
Tim Evans, TKEvans.com, Inc.	|    5 Chestnut Court
tkevans@tkevans.com		|    Owings Mills, MD 21117
http://www.tkevans.com/		|    443-394-3864
http://www.come-here.com/News/	|    


------------- End Forwarded Message -------------


Tim Evans, TKEvans.com, Inc.	|    5 Chestnut Court
tkevans@tkevans.com		|    Owings Mills, MD 21117
http://www.tkevans.com/		|    443-394-3864
http://www.come-here.com/News/	|    



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2005-04-05 17:24 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-04-05 10:35 Resend: MASQUERADE: Route sent us somewhere else Tim Evans
2005-04-05 14:50 ` Jason Opperisano
2005-04-05 16:12   ` Tim Evans
2005-04-05 17:03     ` Jason Opperisano
2005-04-05 17:24       ` Tim Evans
  -- strict thread matches above, loose matches on Subject: below --
2005-04-04 21:55 Tim Evans
2005-04-05  4:49 ` Jason Opperisano

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.