From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?iso-8859-1?Q?KUCKAERTZ_R=E9gis_-_NVISION?= Subject: RE: Port forwarding Date: Fri, 17 Sep 2004 15:52:37 +0200 Sender: netfilter-bounces@lists.netfilter.org Message-ID: References: <1095428035.1886.36.camel@wolfpack.ljm.dom> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1095428035.1886.36.camel@wolfpack.ljm.dom> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org > is it possible that $REAL_IP is a local IP address on the > machine running netfilter? the reason i ask is that the > packet counters on the FORWARD chain are zero (whereas INPUT > and OUTPUT are over 40000). Unfortunately, it is not. Really weird, since packets are correctly DNAT'ed _before_ going through the filter rules, then the kernel should detect that they are not intended to it, neh? I tried tcpdump'ing the $REAL_IP and $REAL_PORT, but then nothing matched the filter. I must have forgot one thing, since _it worked_ in the past!! :'( Thanks for your help! > > -j > > -- > Jason Opperisano > >