Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Alexandru Dragoi <alex@zoomnet.ro>
To: "moniacheli@tiscali.it" <moniacheli@tiscali.it>
Cc: netfilter@lists.netfilter.org
Subject: Re: Iptables SNAT for pkt generated by internal process
Date: Tue, 16 May 2006 19:56:26 +0300	[thread overview]
Message-ID: <446A043A.70700@zoomnet.ro> (raw)
In-Reply-To: <25385417.1147796015381.JavaMail.root@ps20>



moniacheli@tiscali.it wrote:

>I think I could use these commands:
>
>iptables -t mangle -A OUTPUT -p udp --dport 514 -j MARK --set-mark 13
>iptables -t nat -A POSTROUTING -- mark 13 -SNAT x.x.x.x
>
>I tried, but I had this problem on first command:
>"Couldn't load match `MARK':/lib//iptables/libipt_MARK.so: cannot open 
>shared object file: No such file or directory"
>
>Are the commands above rigth and is it sufficient to copy libipt_MARK.
>so into :/lib//iptables/ directory to solve my problem?
>
>Thanks a lot to Alexandru Dragoi
>
>Bye Monia
>
>----Messaggio originale----
>Da: alex@zoomnet.ro
>Data: 16/05/2006 13.00
>A: "moniacheli@tiscali.it"<moniacheli@tiscali.it>
>Cc: <netfilter@lists.netfilter.org>
>Ogg: Re: Iptables SNAT for pkt generated by internal process
>
>moniacheli@tiscali.it wrote:
>
>  
>
>>I would like to use iptables to translate the source of IP datagrams 
>>generated inside a router for some particular applications (such as 
>>syslog: protocol UDP, destination port 514). I thought to use an 
>>iptables rule defined by an OUTPUT chain (which let manipulate 
>>    
>>
>datagram 
>  
>
>>generated from local process) and by the target SNAT (which let to 
>>translate ip source) -> iptables -t nat -A OUTPUT -p udp --dport 514 -
>>    
>>
>j 
>  
>
>>SNAT --to x.x.x.x. The problem is that the OUTPUT chain cannot be 
>>    
>>
>used 
>  
>
>>with the target SNAT!
>>Has anybody any idea about which is the best and simplest way to get 
>>the result described above?
>>
>>Thanks for Your collaboration.
>>Monia Cheli
>>
>>
>>
>>
>>		
>>Tiscali ADSL 4 Mega Flat 
>>
>>Naviga senza limiti a 19,95 Euro al mese con 4 Megabps di velocita'. 
>>    
>>
>Attiva subito: hai 2 MESI di canone adsl GRATIS!
>  
>
>>In piu', se sei raggiunto dalla rete Tiscali, telefoni senza pagare 
>>    
>>
>il canone Telecom. 
>  
>
>>Scopri subito come risparmiare! 
>>
>>http://abbonati.tiscali.it/prodotti/adsl/tc/4flat/
>>	
>>
>> 
>>
>>    
>>
>You do SNAT in POSTROUTING. Local generated packets also enter
>POSTROUTING. You may want to match source ip or .. you can mark 
>packets
>in mangle OUTPUT, and then SNAT in POSTROUTING matching only the mark
>value with mark match.
>
>
>
>
>
>
>
>
>		
>Tiscali ADSL 4 Mega Flat 
>
>Naviga senza limiti a 19,95 Euro al mese con 4 Megabps di velocita'. Attiva subito: hai 2 MESI di canone adsl GRATIS!
>
>In piu', se sei raggiunto dalla rete Tiscali, telefoni senza pagare il canone Telecom. 
>
>Scopri subito come risparmiare! 
>
>http://abbonati.tiscali.it/prodotti/adsl/tc/4flat/
>	
>
>  
>
Try

iptables -t nat -A POSTROUTING -m mark --mark 13 -SNAT x.x.x.x



  reply	other threads:[~2006-05-16 16:56 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-05-16 16:13 Iptables SNAT for pkt generated by internal process moniacheli
2006-05-16 16:56 ` Alexandru Dragoi [this message]
  -- strict thread matches above, loose matches on Subject: below --
2006-05-16  9:38 moniacheli
2006-05-16  9:42 ` Alexandru Dragoi
2006-05-16 11:00 ` Alexandru Dragoi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=446A043A.70700@zoomnet.ro \
    --to=alex@zoomnet.ro \
    --cc=moniacheli@tiscali.it \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox