NetFilter
[Top] [All Lists]

Re: Logging NAT Translations

To: "Jan Engelhardt" <jengelh@linux01.gwdg.de>
Subject: Re: Logging NAT Translations
From: "Craig Bernstein" <cbernstein@cbernstein.com>
Date: Wed, 6 Jun 2007 00:15:54 -0700
Cc: netfilter@lists.netfilter.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <Pine.LNX.4.61.0706060759470.1547@yvahk01.tjqt.qr>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
References: <ae1f24730705182015j533102bah985e9ad0e905cd2a@mail.gmail.com> <Pine.LNX.4.61.0705222208440.4452@yvahk01.tjqt.qr> <ae1f24730706051910o2538955drfc7ec59cf9aa3927@mail.gmail.com> <Pine.LNX.4.61.0706060759470.1547@yvahk01.tjqt.qr>
Sender: netfilter-bounces@lists.netfilter.org
On 6/5/07, Jan Engelhardt <jengelh@linux01.gwdg.de> wrote:
iptables -t nat -N ydm1
iptables -t nat -A ydm1 -j LOG "[Adress got SNATed to 134.76.13.21] "
iptables -t nat -A ydm1 -j SNAT --to 134.76.13.21

iptables -t nat -A POSTROUTING <-d condition -m condition or whatever> -j ydm1

It already was a complete example. When you SNAT, you know you do.

--to-source can be (and is, in this case) a range of IP addresses.  I
know I SNATed, but not to which source IP address and port.

--
...Craig


<Prev in Thread] Current Thread [Next in Thread>