All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Martin A. Brown" <mabrown-lartc@securepipe.com>
To: lartc@vger.kernel.org
Subject: Re: [LARTC] iptables, nat and traffic shaping woes
Date: Tue, 08 Oct 2002 19:29:26 +0000	[thread overview]
Message-ID: <marc-lartc-103410543312301@msgid-missing> (raw)
In-Reply-To: <marc-lartc-103410351409950@msgid-missing>

Aaron,

Visit the kernel packet traveling diagram linked from 
http://www.docum.org/.  This may answer your question.  If not, then 
explain to us what you are using each of the tools for.

It sounds like you are using

  iptables -t nat -j MASQUERADE   (or something like that; maybe SNAT?)
  iptables -t mangle ???          (what are you doing with mangle)
  tc

 : As I try to solve my problems with iptables, nat and traffic shaping (with
 : ip accounting thrown intot he mix) a friend of mine just sent this claim.
 : Is it true?  Will I have to step back to ipchains, or is there a way to
 : force packets through the traffic shaping filters using iptables?

Without knowing what exactly you are trying to do, we can't answer your 
question, and certainly can't comment on the veracity of your friend's 
statement.

As a general guideline though, if you can think of a way to do something 
with ipchains, you can probably do something similar with iptables (and 
usually it's easier with iptables).

 : > If you are using iptables, you MUST forget it, or change to
 : > ipchains, because masq is done by nat table, and shaping is done by
 : > mangle table. I cannot found any way to drive the packet 1. thru
 : > nat, than mangle, instead of using OUTPUT and FORWARD.

Good luck,

-Martin

-- 
Martin A. Brown --- SecurePipe, Inc. --- mabrown@securepipe.com


_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

      parent reply	other threads:[~2002-10-08 19:29 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-08 18:57 [LARTC] iptables, nat and traffic shaping woes Aaron Clausen
2002-10-08 19:16 ` Stef Coene
2002-10-08 19:29 ` Martin A. Brown [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=marc-lartc-103410543312301@msgid-missing \
    --to=mabrown-lartc@securepipe.com \
    --cc=lartc@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.