LARTC
[Top] [All Lists]

Re: [l7-filter-developers] [LARTC] Use l7-filter on router performing NA

To: John Philips <johnphilips42@yahoo.com>
Subject: Re: [l7-filter-developers] [LARTC] Use l7-filter on router performing NAT?
From: Amin Azez <azez@ufomechanic.net>
Date: Fri, 19 Jan 2007 09:24:05 +0000
Cc: lartc@mailman.ds9a.nl, l7-filter-users@lists.sourceforge.net, l7-filter-developers@lists.sourceforge.net
Delivered-to: sp-com-lists@consult.net
Delivered-to: lartc-list@securepoint.com
Delivered-to: lartc@outpost.ds9a.nl
In-reply-to: <503831.31961.qm@web57812.mail.re3.yahoo.com>
List-archive: <http://mailman.ds9a.nl/pipermail/lartc>
List-help: <mailto:lartc-request@mailman.ds9a.nl?subject=help>
List-id: "Mailinglist of the Linux Advanced Routing &amp; Traffic Control project" <lartc.mailman.ds9a.nl>
List-post: <mailto:lartc@mailman.ds9a.nl>
List-subscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe>
List-unsubscribe: <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe>
References: <503831.31961.qm@web57812.mail.re3.yahoo.com>
Sender: lartc-bounces@mailman.ds9a.nl
User-agent: Thunderbird 1.5.0.9 (X11/20070103)
POSTROUTING chain of which table?
NAT should not affect things, as long as - as you say - both directions
are going through the box.

It sounds like you are "not sure" if it's working.
Use connmark target too to save the mark in the conntrack and look in
/proc/net/ip_conntrack
Also use iptables -vn ... -L
to see that l7 count go up as more packets for matched conntracks go by.

Sam

* John Philips wrote, On 17/01/07 16:37:
> Hey guys,
>
> Here's an easy one.
>
> Is it possible to use the l7-filter extension on a box
> that performs NAT?  The HOWTO says the filter only
> works 100% of the time if it can see both sides of the
> connection.  I tried putting the l7 MARK rules in the
> POSTROUTING chain on a box that does NAT and it does
> successfully mark some packets.  I'm not 100% sure if
> it's working, or if it should work this way.
>
> I've searched the mailing list archives and Google but
> haven't found an answer.
>
> Thanks!
>
>
>  
> ____________________________________________________________________________________
> Never miss an email again!
> Yahoo! Toolbar alerts you the instant new Mail arrives.
> http://tools.search.yahoo.com/toolbar/features/mail/
> _______________________________________________
> LARTC mailing list
> LARTC@mailman.ds9a.nl
> http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc
>
> -------------------------------------------------------------------------
> Take Surveys. Earn Cash. Influence the Future of IT
> Join SourceForge.net's Techsay panel and you'll get the chance to share your
> opinions on IT & business topics through brief surveys - and earn cash
> http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
> _______________________________________________
> L7-filter-developers mailing list
> L7-filter-developers@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/l7-filter-developers
>   

_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

<Prev in Thread] Current Thread [Next in Thread>