Re: SNAT --random & fully is not actually random for ips

2016-11-28 Thread Denys Fedoryshchenko
On 2016-11-28 13:29, Pablo Neira Ayuso wrote: On Mon, Nov 28, 2016 at 01:12:07PM +0200, Denys Fedoryshchenko wrote: On 2016-11-28 13:06, Pablo Neira Ayuso wrote: >Why does your patch reverts NF_NAT_RANGE_PROTO_RANDOM_FULLY? Ops, sorry i just did mistake with files, actually it is in reverse (

Re: SNAT --random & fully is not actually random for ips

2016-11-28 Thread Pablo Neira Ayuso
On Mon, Nov 28, 2016 at 01:12:07PM +0200, Denys Fedoryshchenko wrote: > On 2016-11-28 13:06, Pablo Neira Ayuso wrote: > >Why does your patch reverts NF_NAT_RANGE_PROTO_RANDOM_FULLY? > > Ops, sorry i just did mistake with files, actually it is in reverse ( did > this patch, and it worked properly

Re: SNAT --random & fully is not actually random for ips

2016-11-28 Thread Denys Fedoryshchenko
On 2016-11-28 13:06, Pablo Neira Ayuso wrote: On Mon, Nov 28, 2016 at 12:45:59PM +0200, Denys Fedoryshchenko wrote: Hello, I noticed that if i specify -j SNAT with options --random --random-fully still it keeps persistence for source IP. So you specify both? Actually truly random src ip

Re: SNAT --random & fully is not actually random for ips

2016-11-28 Thread Pablo Neira Ayuso
On Mon, Nov 28, 2016 at 12:45:59PM +0200, Denys Fedoryshchenko wrote: > Hello, > > I noticed that if i specify -j SNAT with options --random --random-fully > still it keeps persistence for source IP. So you specify both? > Actually truly random src ip required in some scenarios like links