Re: SNAT for local generated traffic

2002-04-01 Thread Henrik Nordstrom

Harald Welte wrote:
 
 On Sun, Mar 31, 2002 at 06:10:35PM +0200, Henrik Nordstrom wrote:
  Right.. SNAT was rejected by Harald as he sees no use of it. My original
  patch posted on the netfilter-devel mailinglist supports both for
  symmetry.
 
 snat on locally-geerated packets has always beeen working in the
 POSTROUTING chain of the nat table.

Right.. it was SNAT in INPUT you rejected.. to NAT the source address of
received traffic. I am confusing myself..

Regards
Henrik




Re: SNAT for local generated traffic

2002-03-31 Thread Harald Welte

On Sun, Mar 31, 2002 at 06:10:35PM +0200, Henrik Nordstrom wrote:
 Right.. SNAT was rejected by Harald as he sees no use of it. My original
 patch posted on the netfilter-devel mailinglist supports both for
 symmetry.

snat on locally-geerated packets has always beeen working in the 
POSTROUTING chain of the nat table.

You just need to match the packets on -s my_local_ip_address.

I don't see a reason why this functionality should be replicated.

 Regards
 Henrik

-- 
Live long and prosper
- Harald Welte / [EMAIL PROTECTED]   http://www.gnumonks.org/

GCS/E/IT d- s-: a-- C+++ UL$ P+++ L$ E--- W- N++ o? K- w--- O- M+ 
V-- PS++ PE-- Y++ PGP++ t+ 5-- !X !R tv-- b+++ !DI !D G+ e* h--- r++ y+(*)