From: Pete Kay <petedao@gmail.com>
To: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Cc: netfilter@vger.kernel.org
Subject: Re: question about NAT rule
Date: Wed, 23 Jun 2010 09:57:32 +0800 [thread overview]
Message-ID: <AANLkTinOd_6m6UvbqKcB3v2-FinNQzHUmhymFE9Z5RHm@mail.gmail.com> (raw)
In-Reply-To: <4C20D263.2050502@plouf.fr.eu.org>
Hi,
I guess I may have misunderstood the purpose of the
netfilter-conntrack module. What I would like to do is to set up a
alot of iptables NAT rules ( > 10K at 500 rules (add/drop)/s). Using
the system iptables command is not going to be fast enough for me.
All I want is to deliver the packets received from specific IP:port to
another IP:port. Therefore, I am looking into using
netfilter-conntrack api to actually "set" those rules dynamically. Is
this the right approach in doing that?
Could someone please give me some suggestions?
Thanks,
P
On Tue, Jun 22, 2010 at 11:10 PM, Pascal Hambourg
<pascal.mail@plouf.fr.eu.org> wrote:
> Hello,
>
> Pete Kay a écrit :
>>
>> I have the following NAT rule set up :
>>
>> udp 17 12 src=192.168.1.102 dst=192.168.1.140 sport=7390
>> dport=8000 packets=6 bytes=3258 [UNREPLIED] src=192.168.1.140
>> dst=192.168.1.102 sport=10000 dport=9000 packets=0 bytes=0 mark=0
>> secmark=0 use=2
>
> This is not a NAT rule but a conntrack entry.
>
>> What I am expecting to achieve is that when udp packets go from
>> 192.168.1.102:7390 to 192.168.1.140:8000, the conntrack module would
>> redirect the packet to 192.168.1.102:9000, but it is not happening.
>>
>> Does anyone know what is wrong?
>
> It is not happenning because of the above conntrack entry that says
> otherwise and already exists for these packets, so iptables NAT rules
> are ignored. You must first delete the conntrack entry with
> conntrack-tools or by not transmitting related packets until it expires.
> Then the next packet will hit the iptables NAT rules and create a new
> conntrack entry accordingly.
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
next prev parent reply other threads:[~2010-06-23 1:57 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-06-22 14:20 question about NAT rule Pete Kay
2010-06-22 15:10 ` Pascal Hambourg
2010-06-23 1:57 ` Pete Kay [this message]
2010-06-28 17:42 ` Anatoly Muliarski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=AANLkTinOd_6m6UvbqKcB3v2-FinNQzHUmhymFE9Z5RHm@mail.gmail.com \
--to=petedao@gmail.com \
--cc=netfilter@vger.kernel.org \
--cc=pascal.mail@plouf.fr.eu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).