From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Leonid Zeitlin" Subject: Re: Invalid SACK numbers in NAT'ed packets Date: Thu, 24 Apr 2008 12:09:04 +0300 Message-ID: <00c101c8a5ea$d83213f0$5101a8c0@csltd.intranet> References: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; format="flowed"; charset="us-ascii"; reply-type="original" To: Jozsef Kadlecsik Cc: netfilter@vger.kernel.org Hi Jozsef, Thanks for your answer. > or use IPV4OPTSTRIP for the SYN packets sent/received in this direction as > a selective workaround for the problem. What is IPV4OPTSTRIP? How can I get it? It's not in standard iptables (not the one that I have anyway), and I can't find it at the netfilter site either. Thanks, Leonid