From mboxrd@z Thu Jan 1 00:00:00 1970 From: horape@tinuviel.compendium.com.ar Subject: Re: DNATing packets sent to the NATing box Date: Sun, 14 Dec 2003 10:52:11 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20031214135211.GA11695@tinuviel.compendium.com.ar> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: Content-Disposition: inline Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: netfilter@lists.netfilter.org > > Yes, and I've added a rule like this: > > /sbin/iptables -t nat -A PREROUTING -j LOG and don't see the packets. > Ummmm > if you ADD the rule above after the rule that is re-routing the packe= t,=20 > no ... you wont see the packets. Try=20 > iptables -t nat -I PREROUTING (line number) > where (line number) is less than the line on which your DNAT line occurr= s. > (see iptables -t nat --line-numbers -v ) I'm really replacing the DNAT rule with the LOG one (only rule in the chain= is the LOG one) Saludos, HoraPe --- Horacio J. Pe=F1a horape@compendium.com.ar horape@uninet.edu