From: "lartc@manchotnetworks.net" <lartc@manchotnetworks.net>
To: lartc@vger.kernel.org
Subject: Re: [LARTC] Iptables Marking Output
Date: Thu, 21 Aug 2003 12:41:35 +0000 [thread overview]
Message-ID: <marc-lartc-106146976129908@msgid-missing> (raw)
In-Reply-To: <marc-lartc-106140581907200@msgid-missing>
Hello Paul,
On Wed, 2003-08-20 at 20:55, paul.walling@ntlworld.com wrote:
<snip>
> So I read the IpTables Tutorial and find it contradicts itself
>
> Section 3.1 table 3.2: suggests that the routing decision is made
> prior to the mangle happening. This appears to be what I can see happening.
> Hence we can never find a route in our table and this would result in
> Network Unreachable.
>
> Section 6.2 table 6.1 suggests that the mangle of OUTPUT happens
> prior to the routing decision. I don't think this is true because otherwise
> the Mark would be set to 1 and the frame would have been routed correctly
> to 172.21.1.11. Also the theory is backed up by the fact that the ping on
> eth2 was routed out eth2 but with an incorrect source address. The source
> address being added as a result of the routing decision.
This is an issue which I have been trying to resolve for some time ...
you are correct that the routing decision is made prior to a packet
traversing OUTPUT, therefore your attempt to mark and route on locally
generated packets will not work.
two solutions exist:
(1) on the netfilter sight, you'll find a patch from Cédric de Launois
which allows you to select the interface:
iptables -A POSTROUTING -t mangle -p icmp -j ROUTE --iface eth1
(2) you can mark in OUTPUT and then fiddle in the POSTROUTING chain:
iptables --append OUTPUT --table mangle --jump MARK --set-mark 0x2
iptables --append POSTROUTING --table nat --match mark --mark 0x2 \
--jump SNAT --to-source 192.168.1.100
I have been dreaming of a new netfilter target called rt_lookup that
would force a route lookup using the all the packet characteristics as
it traverses the NAT table of the POSTROUTING chain -- regrettably, I
have not had the time to investigate whether it is even possible!
Ciao
Charles
> Now I am very much a newcomer to routing so have probably misunderstood the
> entire principles. Could someone confirm if what I am trying to do is
> correct or if I have completely gone mad and missed the point.
> (which wouldn't be the first time !)
>
> Many thanks in advance
>
> Paul.
>
>
> -----------------------------------------
> Email provided by http://www.ntlhome.com/
>
>
> _______________________________________________
> LARTC mailing list / LARTC@mailman.ds9a.nl
> http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/
prev parent reply other threads:[~2003-08-21 12:41 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-08-20 18:55 [LARTC] Iptables Marking Output paul.walling
2003-08-21 12:41 ` lartc [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=marc-lartc-106146976129908@msgid-missing \
--to=lartc@manchotnetworks.net \
--cc=lartc@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.