From: "Stephen Bylo" <stephenbylo@yahoo.com.sg>
To: Ramin Dousti <ramin@cannon.eng.us.uu.net>
Cc: netfilter@lists.netfilter.org
Subject: Re: DNAT/SNAT & existing connections
Date: Fri, 18 Jul 2003 09:09:31 +0800 (CST) [thread overview]
Message-ID: <20030718010931.55307.qmail@web13101.mail.yahoo.com> (raw)
In-Reply-To: <20030717122907.GA30482@cannon.eng.us.uu.net>
Hi!
I have now found what I'm looking for!
eg.: http://mosquitonet.stanford.edu/mip/
Mobile IP creates a tunnel from R through A to (2).
That's what I need. I don't really need a NAT.
Thanx for the help,
Steve
--- Ramin Dousti <ramin@cannon.eng.us.uu.net> wrote:
> On Thu, Jul 17, 2003 at 10:14:43AM +0800, Stephen
> Bylo wrote:
>
> > If I want *existing* UDP connections to be
> diverted, I
> > need to change both the NAT table *and* the
> connection
> > tracking table, is this right? Can somebody tell
> me if
> > this can be done with iptables? Do I have to hack
> the
> > code? I may do so if need be. Is there another NAT
> > sollution out there that can do what I need?
> > Is using a NAT to divert existing UDP streams
> > technically possible?
>
> I think one way of doing this is to reduce the
> conntrack timeout for
> UDP to almost nihil so that you see the effect of
> adding 2 to the nat
> immidiately. But in that case UDP returns would not
> benefit from the
> implicit conntrack structure and you need to allow
> the return traffic
> explicitly.
>
> Ramin
>
> >
> > Thanx for your help.
> > Steve
__________________________________________________
Do You Yahoo!?
Send free SMS from your PC!
http://sg.sms.yahoo.com
next prev parent reply other threads:[~2003-07-18 1:09 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-07-15 10:01 DNAT/SNAT & existing connections Stephen Bylo
2003-07-15 14:04 ` Ramin Dousti
2003-07-16 2:12 ` Stephen Bylo
2003-07-16 2:50 ` Ramin Dousti
2003-07-16 5:25 ` Stephen Bylo
2003-07-16 14:06 ` Ramin Dousti
2003-07-17 2:14 ` Stephen Bylo
2003-07-17 12:29 ` Ramin Dousti
2003-07-18 1:09 ` Stephen Bylo [this message]
2003-07-18 13:59 ` Ramin Dousti
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030718010931.55307.qmail@web13101.mail.yahoo.com \
--to=stephenbylo@yahoo.com.sg \
--cc=netfilter@lists.netfilter.org \
--cc=ramin@cannon.eng.us.uu.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox