LARTC
[Top] [All Lists]

Re: [LARTC] Re: iptables rule not matching after stream begins

To: Bob Beers <bob.beers@gmail.com>
Subject: Re: [LARTC] Re: iptables rule not matching after stream begins
From: Flophouse Joe <flophousejoe-lartc-zvbbfzu@halibutdepot.org>
Date: Mon, 20 Nov 2006 20:00:09 -0500 (EST)
Cc: lartc@mailman.ds9a.nl
Delivered-to: sp-com-lists@consult.net
Delivered-to: lartc-list@securepoint.com
Delivered-to: lartc@outpost.ds9a.nl
In-reply-to: <4f6ba3b0611201646k750995d3oe0cd605890b7f2a7@mail.gmail.com>
List-archive: <http://mailman.ds9a.nl/pipermail/lartc>
List-help: <mailto:lartc-request@mailman.ds9a.nl?subject=help>
List-id: "Mailinglist of the Linux Advanced Routing &amp; Traffic Control project" <lartc.mailman.ds9a.nl>
List-post: <mailto:lartc@mailman.ds9a.nl>
List-subscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe>
List-unsubscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe>
References: <4f6ba3b0611200730j337ad29xc69dd63b205060c4@mail.gmail.com> <4f6ba3b0611201646k750995d3oe0cd605890b7f2a7@mail.gmail.com>
Sender: lartc-bounces@mailman.ds9a.nl
On Mon, 20 Nov 2006, Bob Beers wrote:
 I want to dynamically create DNAT rules for
  RTP streams (port-mapping for a SIP proxy).

Have you considered testing any of the patches from netfilter's
patch-o-matic?

There are two patches that seem promising.  Quoting from the netfilter
website:

http://www.netfilter.org/patch-o-matic/pom-extra.html#pom-extra-rtsp-conntrack
 rtsp-conntrack - RTSP connection tracking and nat helper
 Author: Tom Marshall <tmarshall@real.com>
 Status: Beta - needs some testing and porting to 2.6.x
 This patch adds CONFIG_IP_NF_RTSP: support for the RTSP protocol.
 This allows UDP transports to be setup properly, including RTP and RDT.

http://www.netfilter.org/patch-o-matic/pom-extra.html#pom-extra-sip-conntrack-nat
 ip-conntrack-nat - SIP connection tracking and NAT helper
 Author: Christian Hentschel <chentschel@arnet.com.ar>
 Status: Alpha
 This adds CONFIG_IP_NF_SIP: SIP support module for netfilter
 connection tracking and NAT.
 The SIP conntrack/NAT modules support the connection tracking/NATing of
 the data streams requested on the dynamic RTP/RTCP ports, as well as
 mangling
 of SIP requests/responses.

Joe
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

<Prev in Thread] Current Thread [Next in Thread>