From mboxrd@z Thu Jan 1 00:00:00 1970 From: Patrick McHardy Subject: Re: xt_policy: output policy not valid in PRE_ROUTING and INPUT Date: Mon, 06 Aug 2007 14:30:19 +0200 Message-ID: <46B7145B.4070407@trash.net> References: Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Cc: netfilter-devel@lists.netfilter.org To: Krzysztof Oledzki Return-path: In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org Krzysztof Oledzki wrote: > Hello, > > Is there any reason why it is not possible to use "-m policy --dir out" > in PREROUTING? I tried to do something like: > > -A PREROUTING -m policy --dir out --pol ipsec -j RETURN > -A PREROUTING -p tcp -i $IF_LANBR --dport 80 -j REDIRECT --to-ports 8088 The IPsec policy is selected after routing, which is why can't be used in PREROUTING.