From mboxrd@z Thu Jan 1 00:00:00 1970 From: Oguz Yilmaz Subject: Re: Packets stops traversing after nat PREROUTING Date: Wed, 14 Apr 2010 23:09:33 +0300 Message-ID: References: Mime-Version: 1.0 Return-path: DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:received:message-id:subject:from:to:content-type; bh=BatCWPMLC710tRNcVycKuFjyXx1OrAefOHxnelPQwLg=; b=P4qXVvjZXKrapnwaONNf/HAVulfdUmnoulTnbiYawnGyS1Vg/6GSbW9CjxRIccGPEz 3H+3JHzbLiupqfIpIGZ60Lc60Ssfyhj+3fwSfMnWwgwurcRsA3GKk4fLKjrXq/3TWqMo oxq6vJlwzopj3SFLRlJvD++DCGDrwqmh461v4= In-Reply-To: Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: netfilter@vger.kernel.org Fortunately/unfortunately it was just because of ip_forward being 0. Thanks. On Wed, Apr 14, 2010 at 12:59 PM, Jan Engelhardt wrote: > On Wednesday 2010-04-14 10:30, Oguz Yilmaz wrote: > >>OS is CentOS 5.4 >>Kernel is 2.6.18-164 >> >>Sometimes my firewall blocks the internet. When I inspect I have seen: >>- nat PREROUTING counters increase >>- filter FORWARD counters do not increase >>- nat POSTROUTING counters do not increase >> >>According to the diagram of Engelhardt, >>http://jengelh.medozas.de/images/nf-packet-flow.png, the problem >>should be in Bridging Decision point or acc.to former diagrams in >>Routing Decision point. >> >>I have tried to flush routing cache by "ip ro fl ca". >> >>Problem is recovered only after /etc/init.d/iptables stop / start >> >>I need further cues for deepen the problem, or exact reasons for >>updating/recompling to newer kernel/netfilter. > > We need further cues like the ruleset. >