All of lore.kernel.org
 help / color / mirror / Atom feed
From: Klaus Mark <netfilter@0u.dk>
To: netfilter-devel@lists.netfilter.org
Subject: The question never answered :-)
Date: Wed, 01 Nov 2006 23:01:02 +0100	[thread overview]
Message-ID: <4549191E.6050903@0u.dk> (raw)

Hi there!

I don't know if i got it right the first time, i didn't send from the 
address that mailman/netfilter knows, should you receive this mail 
twice, then i'm sorry :-)

Let me try to describe what my suggestion/question is. I’ll just start
my mentioning that I’m Danish, so I apologies about my lousy English!

I have a system already in production and basically it does double NAT
locally, but I use 2 LINUX servers. If I was able to SNAT in PREROUTING
then I might be able to do this on one box!

I see one problem though, if I SNAT in PREROUTING will I then be able to
NETMAP in PREROUTING too or are we forced to NETMAP in POSTROUTING?

All this is done so the second LINUX server can have tunnels to any
number of overlapping networks, the source being the difference, and
IPSec in 2.6 is satisfied with X number of tunnels to for example
192.168.1.0/24 if the source just differs!

I’m not routing based on the destination, so it would be ok to DNAT in
POSTROUTING.

I’ve been looking for a solution to this problem for a long time, and
I’m wondering why no one has posted a solution to this, the question has
been asked here before, but you’ve never posted any solutions!

Regards Klaus

                 reply	other threads:[~2006-11-01 22:01 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4549191E.6050903@0u.dk \
    --to=netfilter@0u.dk \
    --cc=netfilter-devel@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.