netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Pete Kay <petedao@gmail.com>
To: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
Cc: netfilter@vger.kernel.org
Subject: Re: question about NAT rule
Date: Wed, 23 Jun 2010 09:57:32 +0800	[thread overview]
Message-ID: <AANLkTinOd_6m6UvbqKcB3v2-FinNQzHUmhymFE9Z5RHm@mail.gmail.com> (raw)
In-Reply-To: <4C20D263.2050502@plouf.fr.eu.org>

Hi,

I guess I may have misunderstood the purpose of the
netfilter-conntrack module.  What I would like to do is to set up a
alot of iptables NAT rules ( > 10K at 500 rules (add/drop)/s).  Using
the system iptables command is not going to be fast enough for me.
All I want is to deliver the packets received from specific IP:port to
another IP:port.  Therefore, I am looking into using
netfilter-conntrack api to actually "set" those rules dynamically.  Is
this the right approach in doing that?

Could someone please give me some suggestions?

Thanks,
P

On Tue, Jun 22, 2010 at 11:10 PM, Pascal Hambourg
<pascal.mail@plouf.fr.eu.org> wrote:
> Hello,
>
> Pete Kay a écrit :
>>
>> I have the following NAT rule set up :
>>
>> udp      17 12 src=192.168.1.102 dst=192.168.1.140 sport=7390
>> dport=8000 packets=6 bytes=3258 [UNREPLIED] src=192.168.1.140
>> dst=192.168.1.102 sport=10000 dport=9000 packets=0 bytes=0 mark=0
>> secmark=0 use=2
>
> This is not a NAT rule but a conntrack entry.
>
>> What I am expecting to achieve is that when udp packets go from
>> 192.168.1.102:7390 to 192.168.1.140:8000, the conntrack module would
>> redirect the packet to 192.168.1.102:9000, but it is not happening.
>>
>> Does anyone know what is wrong?
>
> It is not happenning because of the above conntrack entry that says
> otherwise and already exists for these packets, so iptables NAT rules
> are ignored. You must first delete the conntrack entry with
> conntrack-tools or by not transmitting related packets until it expires.
> Then the next packet will hit the iptables NAT rules and create a new
> conntrack entry accordingly.
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>

  reply	other threads:[~2010-06-23  1:57 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-06-22 14:20 question about NAT rule Pete Kay
2010-06-22 15:10 ` Pascal Hambourg
2010-06-23  1:57   ` Pete Kay [this message]
2010-06-28 17:42     ` Anatoly Muliarski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=AANLkTinOd_6m6UvbqKcB3v2-FinNQzHUmhymFE9Z5RHm@mail.gmail.com \
    --to=petedao@gmail.com \
    --cc=netfilter@vger.kernel.org \
    --cc=pascal.mail@plouf.fr.eu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).