All of lore.kernel.org
 help / color / mirror / Atom feed
* The question never answered :-)
@ 2006-11-01 22:01 Klaus Mark
  0 siblings, 0 replies; only message in thread
From: Klaus Mark @ 2006-11-01 22:01 UTC (permalink / raw)
  To: netfilter-devel

Hi there!

I don't know if i got it right the first time, i didn't send from the 
address that mailman/netfilter knows, should you receive this mail 
twice, then i'm sorry :-)

Let me try to describe what my suggestion/question is. I’ll just start
my mentioning that I’m Danish, so I apologies about my lousy English!

I have a system already in production and basically it does double NAT
locally, but I use 2 LINUX servers. If I was able to SNAT in PREROUTING
then I might be able to do this on one box!

I see one problem though, if I SNAT in PREROUTING will I then be able to
NETMAP in PREROUTING too or are we forced to NETMAP in POSTROUTING?

All this is done so the second LINUX server can have tunnels to any
number of overlapping networks, the source being the difference, and
IPSec in 2.6 is satisfied with X number of tunnels to for example
192.168.1.0/24 if the source just differs!

I’m not routing based on the destination, so it would be ok to DNAT in
POSTROUTING.

I’ve been looking for a solution to this problem for a long time, and
I’m wondering why no one has posted a solution to this, the question has
been asked here before, but you’ve never posted any solutions!

Regards Klaus

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2006-11-01 22:01 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-11-01 22:01 The question never answered :-) Klaus Mark

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.