From: Grant Taylor <gtaylor@riverviewtech.net>
To: Mail List - Netfilter <netfilter@lists.netfilter.org>
Subject: Re: Forwarding Problem
Date: Tue, 12 Dec 2006 20:45:10 -0600 [thread overview]
Message-ID: <457F6936.5070900@riverviewtech.net> (raw)
In-Reply-To: <b06b831a0612120453r8e1169fg8cad7f88d4c5c7d0@mail.gmail.com>
(Cross post of my answer on the LARTC mailing list.)
On 12/12/06 06:53, Javier A Toledano wrote:
> Routing Problem
<snip>
> The problem is that forwarding is enabled but when I try to probe
> connectivity from a host in the 10.0.0.0 net , eg 10.0.0.1 making an
> echo request
> to a host in 192.168.10.0 net , eg 192.168.10.49 the icmp packets
> arrive to the linux box (interface eth0) but don't traverset it.
> After I iniate an echo request from 192.168.10.49 to 10.0.0.1, the
> packets iniatated in 10.0.0.0 net starts to traverse the router
> magically.
> It seems that It needs a packet from the 192.168.10.0 to start working.
>
> I would appreciate any idea.
I'm not a CentOS user so I can not say for sure. However I would expect
that (despite what you say) that there is some sort of IPTables stateful
packet inspection going on from your 10/ network to your 192.168/
network. If this is indeed the case and the rule is a basic state of
ESTABLISHED, RELATED, then any traffic from 10/ to 192.168/ AFTER you
sent traffic from 192.168/ to 10/ would be considered RELATED and thus
allowed through.
However, if as you say, there are no IPTables rules in play at all
something else is interfering with your traffic, what it would be, I'm
not sure.
Try running iptables-save to make sure that there are absolutely no
rules in effect any where.
Grant. . . .
prev parent reply other threads:[~2006-12-13 2:45 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-12-12 12:53 Forwarding Problem Javier A Toledano
2006-12-13 2:45 ` Grant Taylor [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=457F6936.5070900@riverviewtech.net \
--to=gtaylor@riverviewtech.net \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox