From: "Javier Prieto Martínez" <javier.prieto.ext@juntadeandalucia.es>
To: Grant Taylor <gtaylor@riverviewtech.net>
Cc: Mail List - Netfilter <netfilter@vger.kernel.org>
Subject: Re: Redirecting ports in a bridge
Date: Mon, 21 Apr 2008 08:55:38 +0200 [thread overview]
Message-ID: <480C3A6A.3090206@juntadeandalucia.es> (raw)
In-Reply-To: <4808B26F.4060205@riverviewtech.net>
Grant Taylor escribió:
> Ok, forgive me for asking. Is this appliance multi-purpose in such
that it is suppose to log and redirect traffic?
Yes, It's multi-purpose:
http://www.eneotecnologia.com/products_en.html?TB_iframe=true&height=510&width=800
* *Firewall & QoS.-* High performance statefull firewall and quality
of service.
* *Web cache & content filter.-* Black and white list mode with LDAP
or AD authentication.
* *VPN.-*L2TP / IPSEC – X.509, NAT Traversal and high availability.
* *IPS / IDS.-* Snort 2.6 based with hardware acceleration.
* *Load balancing.-* LVS based – L3/4 classification, different
algorithms.
* *High availability.-* VRRP (Router mode) and STP (Bridge mode).
* *Malware.-* Antivirus (ClamAV, Kaspersky), antispam (DSPAM,
Mailshell), antispyware (Kaspersky, PCTools or Sunbelt) with
hardware acceleration.
* *NetFlow probe.-* NetFlow v5/9 Probe.
We use it in bridge mode, mainly for traffic logging, and sometimes for
packet filtering.
> As Jan Engelhardt has pointed out so well, you are very likely
dealing with (what I call)
> a "TCP Triangle". If there is not something else in the mix doing
source NATing, you will
> need to do something else to avoid the "TCP Triangle". There are many
different options
> available, one of which is the SNATing like you are referring to
(though I would be careful
> on selecting the packets to SNAT). Another would be to have your
clients connect to IPs on
> LAN 1 that are bound to the router that is DNATing traffic to LAN 2
and then unDNATing the
> replies. You could also have duplicate IPs bound on server 1 and
server 2 and use some
> clustering techniques to alter which MAC address / server the
packet(s) go to, thus
> allowing both servers to answer with the proper IP.
I still want the bridge to be totally transparent, and I don't want to
mess with the real IPs, as I don't want the probe to be a single point
of failure. In fact, it's network cards still work as a bridge when the
machine is down.
I suppose I should use SNAT, then, as you've stated, but it doesn't seem
to work properly. I'm trying that:
# iptables -t nat -A PREROUTING -p tcp -d 192.168.2.1 --dport 80 --to-destination 192.168.2.2:80 -j DNAT
# iptables -t nat -A POSTROUTING -p tcp --sport 80 -s 192.168.2.2 -d 192.168.1.0/24 -j SNAT --to-source 192.168.2.1
next prev parent reply other threads:[~2008-04-21 6:55 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-04-18 9:27 Redirecting ports in a bridge Javier Prieto Martínez
2008-04-18 10:35 ` Jan Engelhardt
2008-04-18 10:55 ` Javier Prieto Martínez
2008-04-18 11:29 ` Jan Engelhardt
2008-04-18 11:41 ` Javier Prieto Martínez
2008-04-18 12:26 ` Marc Cozzi
2008-04-18 12:34 ` Javier Prieto Martínez
2008-04-23 15:25 ` Jan Engelhardt
2008-04-18 14:38 ` Grant Taylor
2008-04-21 6:55 ` Javier Prieto Martínez [this message]
2008-04-22 1:30 ` Grant Taylor
2008-04-22 6:15 ` Javier Prieto Martínez
2008-04-22 14:29 ` Grant Taylor
2008-04-22 15:10 ` Javier Prieto Martínez
2008-04-22 19:24 ` Grant Taylor
2008-04-23 15:24 ` Jan Engelhardt
2008-04-23 17:16 ` Grant Taylor
2008-04-23 18:48 ` Jan Engelhardt
2008-04-23 18:57 ` Grant Taylor
2008-04-24 6:15 ` Javier Prieto Martínez
2008-04-18 14:34 ` Grant Taylor
2008-04-18 14:44 ` Grant Taylor
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=480C3A6A.3090206@juntadeandalucia.es \
--to=javier.prieto.ext@juntadeandalucia.es \
--cc=gtaylor@riverviewtech.net \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox