Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Paul Albert" <palbert@rovingplanet.com>
To: Ramin Dousti <ramin@cannon.eng.us.uu.net>
Cc: netfilter@lists.netfilter.org
Subject: RE: Seeing all packets
Date: Tue, 17 Jun 2003 17:47:50 -0600	[thread overview]
Message-ID: <661F9268BBA8CB4EB92CC12B8C42F06901F64E@pluto.rovingplanet.com> (raw)

Perhaps my definition of session isn't correct.  Is the definition of
session a connection, ie. Something that I can see in
/proc/net/ip_conntrack?  I would like to firewall all of the traffic
that the connection is sending and receiving so that if I were to
dynamically put a policy in place I would disrupt a streaming
connection, say.

So if the packets bypass the NAT table, do they definitely go to the
filter table?
Is there a POM module that will allow me to do DNAT from another table
than NAT?  I thought that I saw one listed, but I could not find it.

Regards,
Paul


-----Original Message-----
From: Ramin Dousti [mailto:ramin@cannon.eng.us.uu.net] 
Sent: Tuesday, June 17, 2003 5:14 PM
To: Paul Albert
Cc: netfilter@lists.netfilter.org
Subject: Re: Seeing all packets


Once the NAT rule kicks in for certain session all the subsequent
packets of that session would bypass the nat rules...

Ramin

On Tue, Jun 17, 2003 at 02:38:55PM -0600, Paul Albert wrote:

> Hi -
> 
> I'm trying to do some firewalling on every packet that goes through 
> our firewall.  We're doing our filtering in the PREROUTING chain (not 
> recommended, I realize), because we must do our firewalling to 
> determine whether we need to NAT a request.  There are times when the 
> NAT PREROUTING chain is bypassed, and I'm not exactly sure why.  The 
> docs say that "it will be bypassed in certain cases," however I cannot

> determine what these cases are.
> 
> Why are the packets getting sent past the NAT PREROUTING chain? Is 
> there a way to send all of the data through this chain?
> 
> Regards,
> Paul
> 


             reply	other threads:[~2003-06-17 23:47 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-06-17 23:47 Paul Albert [this message]
2003-06-18  1:53 ` Seeing all packets Ramin Dousti
  -- strict thread matches above, loose matches on Subject: below --
2003-06-17 20:38 Paul Albert
2003-06-17 23:13 ` Ramin Dousti

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=661F9268BBA8CB4EB92CC12B8C42F06901F64E@pluto.rovingplanet.com \
    --to=palbert@rovingplanet.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=ramin@cannon.eng.us.uu.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox