From: Internet Protocol version Six <inet6@mail.be>
To: netfilter@newkirk.us
Cc: netfilter@lists.netfilter.org
Subject: Re: IPv6 Router and NAT/connection tracking
Date: Sat, 21 Jun 2003 00:27:17 +0200 (GMT+02:00) [thread overview]
Message-ID: <1547190167.1056148037625.JavaMail.Administrator@pumbaa> (raw)
Well, I just tried it, still the same, connections from the
routerbox itself to the Internet (like an IRC server) don't timeout,
but connections to the Internet from a machine on the network do
timeout after a 4 minutes or something and traceroutes to the address
of the machine on the network ends at the router, timing out.
And then I cannot establish a connection anymore unless I tracert6
from the networkmachine to a hostname on the Internet, doesn't even
matter which address I traceroute6 too, aslong as it's an Internet
address and then the whole thing works again..., repeating the same
problem again :(
> ----------------------------------------
> From: Joel Newkirk <netfilter@newkirk.us>
> Sent: Fri Jun 20 08:24:48 GMT+02:00 2003
> To: Internet Protocol version Six <inet6@mail.be>
> Subject: Re: IPv6 Router and NAT/connection tracking
>
>
> On Wed, 2003-06-18 at 20:09, Internet Protocol version Six wrote:
> > I'm connected via IPv6-in-IPv4 and I have a /48 assigned to this
> > box, and I want the box to act as a router for my machines which
> > it's doing nicely, only the conntrack thing is annoying the hell
> > outta me ;) Will that solve it (ACCEPTING in both directions)?
> >
> > And so what you are saying is that I should do this?:
> > iptables -I INPUT -p 41 -j ACCEPT
> > iptables -I OUTPUT -p 41 -j ACCEPT
> > iptables -I PREROUTING -p 41 -j ACCEPT -> not sure about this one
> >
> > or am I wrong/forgetting something? :)
> >
> > Thanks for your help, greatly appreciated
>
> AFAIK that is correct. (however the PREROUTING one wouldn't work, would
> need to be NAT table, and would be unnecessary anyway since that chain
> is supposed to have an ACCEPT policy - NAT in NAT table, filter in
> FILTER table) The two rules, INPUT and OUTPUT, should overcome any
> failure of the state machine to recognize intermittent tunnel traffic as
> ESTABLISHED.
>
> Regarding 'internal' ipv6 traffic within your network, I suspect you
> should be using ip6tables there if needed. (ip6tables won't see 6in4
> tunnel traffic though, since the tunnel itself is IPv4)
>
> I haven't configured my gateway as an ipv6 router yet, however. I have
> a single address ATM from freenet6. When I get the chance to tinker (a
> few weeks from now at least) I want to configure ipv6 on my desktop as
> well as my server and see what there is to see.
>
> j
>
>
>
>
-----------------------------------------------------
Mail.be, WebMail and Virtual Office
http://www.mail.be
next reply other threads:[~2003-06-20 22:27 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-06-20 22:27 Internet Protocol version Six [this message]
-- strict thread matches above, loose matches on Subject: below --
2003-06-19 0:09 IPv6 Router and NAT/connection tracking Internet Protocol version Six
2003-06-20 6:24 ` Joel Newkirk
2003-06-18 21:05 Internet Protocol version Six
2003-06-18 22:28 ` Joel Newkirk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1547190167.1056148037625.JavaMail.Administrator@pumbaa \
--to=inet6@mail.be \
--cc=netfilter@lists.netfilter.org \
--cc=netfilter@newkirk.us \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox