From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
To: netfilter@lists.netfilter.org
Subject: Re: Redirecting traffic from a non-existent IP
Date: Mon, 05 Jun 2006 13:44:37 +0200 [thread overview]
Message-ID: <44841925.6000200@plouf.fr.eu.org> (raw)
In-Reply-To: <44841524.1070505@gmx.de>
Hello,
Julian Hagenauer a écrit :
> Hi,
> i am running Linux 2.6.11.12-xen0 (binary distribution).
> I want to route all Traffic destined to 192.168.1.5 to 192.168.1.3.
> 192.168.1.5 is a non-existent IP/host, 192.168.1.3 is a Xen-VM running
> on localhost, so 192.168.1.5 should act as a kind of alias for
> 192.168.1.3 and be accessible from localhost.
[...]
> iptables -t nat -A PREROUTING -d $MAP_FROM -j DNAT --to $MAP_TO
> echo "Aktuelle Nat-Regeln:"
> iptables -t nat -L
>
> But ping 192.168.1.5 or ssh 192.168.1.5 still does not work.
> I have no clue what's wrong.
I guess the problem is ARP. If nothing replies to the ARP requests for
192.168.1.5 sent by th host which want to send a packet to this address,
then IP packets for this destination aren't even sent (that should
produce Host Unreachable error messages).
Possible workarounds :
- set up some ARP daemon on the network that will reply for 192.168.1.3
- set a static ARP entry in the senders' ARP table (heavy)
- set a static route to 192.168.1.5 with gateway 192.168.1.3 (I know,
that's ugly)
- maybe it is possible to use arptables on the NAT box to make it reply
to the ARP requests (I don't know anything about this)
I guess IP aliasing is not an option.
next prev parent reply other threads:[~2006-06-05 11:44 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-06-05 11:27 Redirecting traffic from a non-existent IP Julian Hagenauer
2006-06-05 11:44 ` Pascal Hambourg [this message]
-- strict thread matches above, loose matches on Subject: below --
2006-06-05 11:34 Sietse van Zanen
2006-06-05 13:16 Eliot, Wireless and Server Administrator, Great Lakes Internet
2006-06-05 13:45 Eliot, Wireless and Server Administrator, Great Lakes Internet
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=44841925.6000200@plouf.fr.eu.org \
--to=pascal.mail@plouf.fr.eu.org \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.