* Tom Eastep wrote: > On 12/13/10 6:58 AM, Nathan Gibbs wrote: >>> >>> >> I'm still thinking about this, and "might" have a solution. >> >> First a couple of questions. >> 1. In iptables, does the nat table get processed before the filter table? > > Yes -- please see http://www.shorewall.net/Documentation_Index.html >> 2. Could I call a chain in the nat table from the filter table? > > No. > Ok, thanks Tom. Those were the answers I thought I'd get, but I wanted to make sure before making a complete fool of myself.
Here is how my shorewall macro would do it now. 14000+ address specific REDIRECT rules in the nat table. 14000+ address specific DROP rules in the filter table. Here is how I "think" it could be done in iptables. In the nat ables. A chain that just does the REDIRECT than a DROP. Will I need a port specific ACCEPT between the REDIRECT and DROP? 14000+ address specific rules that call this chain in nat PRROUTING. In the filter table. I wouldn't need anything to deal with this, because all the action would have already happened in the nat table. Now, if this would work, how do I explain it to shorewall? Of course if it won't work, please tell me why. :-) -- Sincerely, Nathan Gibbs Systems Administrator Christ Media http://www.cmpublishers.com
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Lotusphere 2011 Register now for Lotusphere 2011 and learn how to connect the dots, take your collaborative environment to the next level, and enter the era of Social Business. http://p.sf.net/sfu/lotusphere-d2d
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
