From: Steve <netfilter@arntzen.us>
To: netfilter@lists.netfilter.org
Subject: How to mangle source packet source ports to a fixed range
Date: Fri, 9 Feb 2007 09:15:56 -0600 [thread overview]
Message-ID: <200702090915.56546.netfilter@arntzen.us> (raw)
I have a need to set the source packet's high (unprivileged) source ports to a
fixed range of high ports on a firewall providing NAT.
The goal is to be able to identify the inside machines at the destination
after NAT has changed the addresses. This is for identification only. I do
not need to connect back to the machines inside the firewall. I realize this
may break certain protocols which may use dedicated unprivileged ports.
i.e.:
PREROUTING -i eth0 -p tcp -m tcp -s 192.168.0.x --sport 1024:65535 -j
REDIRECT --to-ports 2000-2200
The above modifies the destination port based on the source port. I wish to
modify the source port ( --from-ports ? ).
By already knowing the range of high ports used per internal IP address, I can
tell which machine inside is sending the data.
If someone knows another way of doing this, I would appreciate any
suggestions.
Thanks,
Steve.
next reply other threads:[~2007-02-09 15:15 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-02-09 15:15 Steve [this message]
2007-02-09 15:34 ` How to mangle source packet source ports to a fixed range Pascal Hambourg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200702090915.56546.netfilter@arntzen.us \
--to=netfilter@arntzen.us \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.