From mboxrd@z Thu Jan 1 00:00:00 1970 From: Olivier GRALL Subject: [IPTABLES] Symmetric NAT ? Date: Tue, 18 Oct 2005 09:07:55 +0200 Message-ID: <43549F4B.2060705@neotip.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii"; format="flowed" To: netfilter@lists.netfilter.org Hi, I was making some tests with STUN when I realize that my NAT box was a simple Linux Box with an IPTABLES rule with a MASQ target. What seemed strange to me was that the STUN result was "Port restricted cone ". I made a new with NATcheck.exe... same result. http://midcom-p2p.sourceforge.net/ I was sure IPTABLES NAT was Symmetric and not Port restricted cone. What about it ? In the "Procceding of NetFilter Developer WorkShop 2004", Harald Welte reported " netfilter however implements (SNAT and MASQ) as ssymmetric. " For me, with MASQ it is Port restricted cone and with SNAT+DNAT it is Symmetric. Is it true ? Thanx, -- Olivier GRALL R&D Engineer *NeoTIP** S.A.* 4, rue Louis de Broglie 22300 Lannion France olivier.grall@neotip.com +33 (0)2 96 48 66 94