From mboxrd@z Thu Jan 1 00:00:00 1970 From: Peter Kaagman Subject: Re: Ipsec and masquerading Date: Wed, 31 Mar 2010 11:43:43 +0200 Message-ID: References: Mime-Version: 1.0 Content-Transfer-Encoding: QUOTED-PRINTABLE Return-path: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:received:message-id:subject:from:to:cc:content-type :content-transfer-encoding; bh=y8SBFMfSSK79+SVCEfwFurwzyNkkBGmuMdzHqyD/dkQ=; b=otqXc2AUwTXHa5br1BwRSy7yZTvlW/5mj+JVd0QxG7a3IlNSUzIRpgKRy8x3qCGdE5 CSUmnbDmxOZ4fCg25TEIHTGeqGCAnU8n3tjhyWIyUHlBP2P3tUHoXpMoBXbHAkISMP1t 0QMuAVPDiLos0aAL0uUyvKZR3D/WqlfsA3MLs= In-Reply-To: Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; charset="iso-8859-1" To: =?ISO-8859-1?Q?Fran=E7ois_Legal?= Cc: netfilter@vger.kernel.org On Wed, Mar 31, 2010 at 9:29 AM, Fran=E7ois Legal wrote: > That would be in your case something like > iptables -t nat -A POSTROUTING -d 10.3.0.0/16 -o $ext_if -j ACCEPT Wow.... virtual kiss for you ;) Was a bit sceptical to be honest, did test simular rules with no effect. But it did the trick :D I'm on the road again. Peter