From: Italo Valcy <italo@dcc.ufba.br>
To: netfilter@vger.kernel.org
Subject: Re: How to use DNAT
Date: Fri, 18 Feb 2011 09:50:26 -0300 [thread overview]
Message-ID: <4D5E6B12.3040003@dcc.ufba.br> (raw)
In-Reply-To: <4D5DB226.7050002@plouf.fr.eu.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi guys,
Em 17-02-2011 20:41, Pascal Hambourg escreveu:
>> Also, bear in mind that the nat table is only consulted for
>> packets with state NEW. If your UDP flow state transitions to
>> ESTABLISHED before your NAT rule is created, the new rule will
>> not be applied to that flow.
>
> Actually it is even stricter : the nat rules are consulted only for the
> first packet of a new flow ("connection"). The next packets skip the nat
> rules even when the flow does not transition to ESTABLISHED (when there
> is no packet in the reply direction).
Yes, you are correct, but I didn't understand this behaviour. I managed
to get the netflow traffic working again by stoping the netflow device,
wainting about one minute and starting again. Almost sure its the exact
explanation above. But, why this behavior???
I think this problem starts happening when I restart the iptables rules
and the traffic keeps going. Maybe in that moment, the packets does not
pass to NAT table anymore. How can I fix it? Do you have any ideias
guys? I'm using the rules generated by fwbuilder to start/restart the
firewall.
Thanks again for the help!
- --
Saudações,
Italo Valcy :: http://wiki.dcc.ufba.br/~ItaloValcy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iEYEARECAAYFAk1eaxIACgkQfidLqjN6RNHpQACgm6ISsVBVByr5PSRT8LSu1WRA
zwUAn1+VtJAxR42LfYS+aVHrTOXMQKbc
=9O4a
-----END PGP SIGNATURE-----
next prev parent reply other threads:[~2011-02-18 12:50 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <184364666.3998.1297982398411.JavaMail.root@tahiti.vyatta.com>
2011-02-17 22:57 ` How to use DNAT Steven Kath
2011-02-17 23:41 ` Pascal Hambourg
2011-02-18 12:50 ` Italo Valcy [this message]
2011-02-19 2:55 ` Atle Solbakken
2011-02-19 5:06 ` Pandu Poluan
2011-02-17 18:47 Italo Valcy
2011-02-17 19:03 ` Jan Engelhardt
2011-02-17 19:17 ` Italo Valcy
2011-02-17 20:05 ` Pascal Hambourg
2011-02-17 21:30 ` Italo Valcy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4D5E6B12.3040003@dcc.ufba.br \
--to=italo@dcc.ufba.br \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox