From mboxrd@z Thu Jan 1 00:00:00 1970 From: Edmund Subject: Re: pktstat and netfilter Date: Wed, 06 Aug 2003 12:02:54 +0800 Sender: netfilter-admin@lists.netfilter.org Message-ID: <3F307DEE.70505@belfordhk.com> References: <3F2F6235.5080100@belfordhk.com> <1060072266.749.8.camel@elendil.intranet.cartel-securite.net> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1060072266.749.8.camel@elendil.intranet.cartel-securite.net> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Netfilter Cedric Blancher wrote: > It's quite wierd as one would like to capture the very traffic that is > sent to the wire or traffic recieved from the wire unaltered, whatever > active ruleset. > What's even weird is that during a www session, most of the packets would originate from my NAT firewall's IP, but one or two (in a sequence) would show a LAN IP. I'm confused as to why this is happening. Has anyone encountered something similar?