From: "Lluís Batlle" <viriketo@gmail.com>
To: netfilter@lists.netfilter.org
Subject: Re: Problem with routing decisions, and multihop
Date: Tue, 5 Jul 2005 07:52:52 +0200 [thread overview]
Message-ID: <45219fb00507042252343deced@mail.gmail.com> (raw)
In-Reply-To: <200507041306.08626.rob0@gmx.co.uk>
Again between lines...
On 7/4/05, /dev/rob0 <rob0@gmx.co.uk> wrote:
> On Monday 04 July 2005 11:54, Lluís Batlle wrote:
> > > >>NE1=192.168.16.0/28
> > > >>NE2=192.168.17.0/28
> > >
> > > Let's see, those are .0-.15 on the last quad.
> > >
> > > >>NLOCAL=192.168.0.0/20
> > >
> > > And this is 0.0 through 15.255 ... IOW, wrong, excluding both $NE1
> > > and $NE2. Try 192.168.16.0/23. It would not hurt for you to brush
> > > up on TCP/IP and subnetting basics.
> >
> > Oh. Is it wrong? I don't understand what's "IOW". Where should I try
> > your proposed subnet? why?
>
> IOW="in other words", a common Internet shorthand.
>
> 192.168.0.0/20, set as $NLOCAL in your iptables script, excludes your
> IP addresses and networks. No packet hitting the rules which refer to
> that value will match, so the rules are ignored.
Why? in the LAN (eth0, 192.168.0.0/20) there are many computers... if
I change it to 192.168.0.0/16, eth1 and eth2 _won't_ be appart
subnetworks! It's important to them to be excluded.
IOW, there must be no intersection between the networks of the different NICs.
>
> The rules to which I am referring:
> $IPTABLES -t nat -A POSTROUTING -o eth1 -s $NLOCAL -j SNAT --to $IPE1
> $IPTABLES -t nat -A POSTROUTING -o eth2 -s $NLOCAL -j SNAT --to $IPE2
> Your SNAT rules.
>
> Change "NLOCAL=192.168.0.0/20" to "NLOCAL=192.168.0.0/16", or as
> previously suggested, "NLOCAL=192.168.16.0/23". I suppose you could
> even omit the source specification altogether:
> $IPTABLES -t nat -A POSTROUTING -o eth1 -j SNAT --to $IPE1
> $IPTABLES -t nat -A POSTROUTING -o eth2 -j SNAT --to $IPE2
Will, that way, the kernel maintain connection-tables for SNAT even
for local connections?
> ### Kids, don't try this at home. Professional stunt driver on a
> ### closed track.
> iptables -N InputLogDrop
> iptables -N ForwardAllow
> iptables -A InputLogDrop -j ACCEPT
> iptables -A FORWARD -j InputLogDrop
> iptables -A ForwardAllow -j LOG
> iptables -A ForwardAllow -p tcp -j REJECT
> iptables -A ForwardAllow -j DROP
> iptables -A INPUT -j ForwardAllow
> ### For my next trick, I will campaign to be elected Prime Minister.
> ### Thank you for your support in the polls.
:)))
> Perhaps it doesn't break anything, but I have read here that only
> packets of --state NEW hit the -t nat PREROUTING chain. I don't know
> about the relationship between connection tracking and NAT.
Can you give a link about that?
>
> "RFC 1918 netblocks" is simply another form of shorthand to refer to
> IPv4 ranges which are reserved for private use, namely 10.0.0.0/8,
> 172.16.0.0/12, and 192.168.0.0/16. I rarely read RFC's myself (but I
> must confess to a fondness for RFC 1149. :) )
Hahaha :)
next prev parent reply other threads:[~2005-07-05 5:52 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-07-04 14:15 Problem with routing decisions, and multihop Lluís Batlle
2005-07-04 14:21 ` Lluis Batle
2005-07-04 14:32 ` Lluis Batle
2005-07-04 15:07 ` /dev/rob0
2005-07-04 15:10 ` /dev/rob0
[not found] ` <45219fb005070408323197bfa4@mail.gmail.com>
2005-07-04 15:32 ` Lluis Batle
2005-07-04 16:33 ` /dev/rob0
2005-07-04 16:54 ` Lluís Batlle
2005-07-04 18:06 ` /dev/rob0
2005-07-05 5:52 ` Lluís Batlle [this message]
2005-07-05 7:46 ` Problem with routing decisions, and multihop (solved) Lluís Batlle
-- strict thread matches above, loose matches on Subject: below --
2005-07-04 14:52 Problem with routing decisions, and multihop LluÃs Batlle i Rossell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=45219fb00507042252343deced@mail.gmail.com \
--to=viriketo@gmail.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.