Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Brian Austin - Standard Universal <brian@standarduniversal.com.au>
To: Thomas Creutz <thomas.creutz@gmx.de>
Subject: Re: multi-wan with conn-mark
Date: Tue, 20 Jan 2009 19:36:53 +1100	[thread overview]
Message-ID: <49758D25.4050703@standarduniversal.com.au> (raw)
In-Reply-To: <497580D4.7000003@gmx.de>

I think the thing to do is
s/nat as you would normally.. then
consider each case of packet flow, and mark the packets accordingly. it 
took me two weeks to achieve that page, I'm no expert.

b


Thomas Creutz wrote:
> Hello Brian
>
> Brian Austin - Standardknit schrieb:
>> see if this helps..
>>
>> http://versa.net.au/index.php?option=com_content&task=view&id=21&Itemid=34 
>>
>>
> thanks for your link :-)
>
> the main problem for me is, that most howto's use external 
> dsl-routers. But a main different think i see on this howto is, that 
> the author make on some more points connmarks :-/ all other howto's i 
> found make them only in the PREROUTING and POSTROUTING chains.
>
> other question to this topic: when i switch to SNAT for the default 
> gateway, have i also so connmark and SNAT the other routers in the 
> local area network? i dont think so, while i dont need NAT on the lan.
>
> But when I look over some snippets I see some think like this
>
> http://209.85.129.132/search?q=cache:3hmyGB8Jr5QJ:www.thaiadmin.org/board/index.php%3Ftopic%3D84571.0+iptables+%2B%22conn-mark%22+SNAT+port+forwarding&hl=de&ct=clnk&cd=16&gl=de&client=firefox-a 
>
> http://www.workman-engineering.com/Files/S35firewall
>
> Thomas

      reply	other threads:[~2009-01-20  8:36 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-01-19 16:45 multi-wan with conn-mark Thomas Creutz
     [not found] ` <4974F82F.4040309@standarduniversal.com.au>
2009-01-20  7:44   ` Thomas Creutz
2009-01-20  8:36     ` Brian Austin - Standard Universal [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=49758D25.4050703@standarduniversal.com.au \
    --to=brian@standarduniversal.com.au \
    --cc=thomas.creutz@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox