* Tom Eastep wrote:
> On 12/13/10 6:58 AM, Nathan Gibbs wrote:
>>>
>>>
>> I'm still thinking about this, and "might" have a solution.
>>
>> First a couple of questions.
>> 1. In iptables, does the nat table get processed before the filter table?
> 
> Yes -- please see http://www.shorewall.net/Documentation_Index.html
>> 2. Could I call a chain in the nat table from the filter table?
> 
> No.
> 
Ok, thanks Tom.
Those were the answers I thought I'd get, but I wanted to make sure before
making a complete fool of myself.

Here is how my shorewall macro would do it now.
14000+ address specific REDIRECT rules in the nat table.
14000+ address specific DROP rules in the filter table.


Here is how I "think" it could be done in iptables.
In the nat ables.
A chain that just does the REDIRECT than a DROP.
Will I need a port specific ACCEPT between the REDIRECT and DROP?
14000+ address specific rules that call this chain in nat PRROUTING.

In the filter table.
I wouldn't need anything to deal with this, because all the action would have
already happened in the nat table.

Now, if this would work, how do I explain it to shorewall?
Of course if it won't work, please tell me why.
:-)

-- 
Sincerely,

Nathan Gibbs

Systems Administrator
Christ Media
http://www.cmpublishers.com


Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Lotusphere 2011
Register now for Lotusphere 2011 and learn how
to connect the dots, take your collaborative environment
to the next level, and enter the era of Social Business.
http://p.sf.net/sfu/lotusphere-d2d
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to