All of lore.kernel.org
 help / color / mirror / Atom feed
* delete NAT conntrack entry.
@ 2007-05-10  7:10 ???
  2007-05-10  9:52 ` Jan Engelhardt
  0 siblings, 1 reply; 5+ messages in thread
From: ??? @ 2007-05-10  7:10 UTC (permalink / raw)
  To: netfilter


Hello

We have some problems with nat.
We want to relay "udp packet" from a host to other host using SNAT, DNAT.

iptables -t nat -A PREROUTING -p udp -d PACKET.RELAY.HOST.IP --dport 10000
-j DNAT --to-destination TO.OTHER.HOST.IP:10000 
iptables -t nat -A POSTROUTING -p udp -d TO.OTHER.HOST.IP --dport 10000 -j
SNAT --to-source PACKET.RELAY.HOST.IP:10000

It works well. But after removing the rules, packet still transferred. I can
find the conntrack entry in /proc/net/stat/ip_conntrack.
We know libnfnetlink & libnetfilter_conntrack with kernel 2.6 can delete
conntrack entries from userspace. But we use Redhat linux 2.4.21-32.EL.
How can I delete specified conntrack entry in kernel 2.4 without kernel code
??

Cheers,
Seongwoo Park







^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-05-10 16:16 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-05-10  7:10 delete NAT conntrack entry ???
2007-05-10  9:52 ` Jan Engelhardt
2007-05-10 11:14   ` Wakko Warner
2007-05-10 12:48     ` Jan Engelhardt
2007-05-10 16:16       ` Wakko Warner

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.