Linux Netfilter discussions
 help / color / mirror / Atom feed
* De-SNAT-ing and DNAT
@ 2003-02-25 16:59 J. A. Landamore
  2003-02-25 19:03 ` Cedric Blancher
  0 siblings, 1 reply; 3+ messages in thread
From: J. A. Landamore @ 2003-02-25 16:59 UTC (permalink / raw)
  To: netfilter

Please excuse my ignorance with this, but I'm trying to pick the bones out of an 
iptables configuration that has been dropped in my lap.

I have a lan of machines on a 192.168. network with an iptables box to the real 
world.  If I apply SNAT I can map all the internal addresses to the one real 
world facing assigned address.  I assume that when packets come back they are 
"de-SNAT"ed before passing back onto the private lan, and that this happens in 
the "PREROUTING" path.  My question is, does the "de-SNAT" happen before or 
after the "PREROUTING" DNAT?

Why, because I need to make a DNAT decision based on the original _source_ 
address, i.e. which machine originally sourced the packet.

Thanks for your help

John Landamore


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-02-25 19:23 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <20030225180802.26030.80793.Mailman@kashyyyk>
2003-02-25 19:23 ` De-SNAT-ing and DNAT Willi Mann
2003-02-25 16:59 J. A. Landamore
2003-02-25 19:03 ` Cedric Blancher

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox