netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Configure ICMP error source address
@ 2016-01-08  9:31 Robert Sander
  2016-01-08 15:24 ` prmarino1
                   ` (2 more replies)
  0 siblings, 3 replies; 11+ messages in thread
From: Robert Sander @ 2016-01-08  9:31 UTC (permalink / raw)
  To: netfilter, netdev

[-- Attachment #1: Type: text/plain, Size: 1232 bytes --]

Hi,

It is possible to change the source address of ICMP error messages
generated by the kernel via
/proc/sys/net/ipv4/icmp_errors_use_inbound_ifaddr. This is currently the
only way to influence the source address as ICMP errors do not travel
through the NAT table (for obvious reasons).

We have the situation that our routers use RFC1918 addresses on their
transfer networks (which should be quite common nowadays to save on
public IPv4 addresses). ICMP errors are generated with RFC1918 source
addresses and therefor never reach the original sender.

Every router has its public IP address bound to dev lo to be reachable
even if any one interface is down. Routing protocols assure that.

Is it a good idea to develop a kernel patch that makes it possible to
select the first IPv4 address on dev lo with scope global as the source
address for ICMP errors? Would that do any harm to the Internet at large?

Regards
-- 
Robert Sander
Heinlein Support GmbH
Schwedter Str. 8/9b, 10119 Berlin

http://www.heinlein-support.de

Tel: 030 / 405051-43
Fax: 030 / 405051-19

Zwangsangaben lt. §35a GmbHG:
HRB 93818 B / Amtsgericht Berlin-Charlottenburg,
Geschäftsführer: Peer Heinlein -- Sitz: Berlin


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 836 bytes --]

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2016-02-15  9:19 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-01-08  9:31 Configure ICMP error source address Robert Sander
2016-01-08 15:24 ` prmarino1
2016-01-08 16:11   ` Hannes Frederic Sowa
2016-01-09  3:57     ` prmarino1
2016-01-09  9:57       ` Hannes Frederic Sowa
2016-01-09 16:41         ` Robert Sander
2016-01-09 22:55           ` Pascal Hambourg
2016-01-09 23:01           ` Hannes Frederic Sowa
2016-01-10 19:12             ` Robert Sander
2016-01-08 16:21 ` Hannes Frederic Sowa
2016-02-15  9:13 ` Robert Sander

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).