Re: Iptables problem

From: Robert Nichols (SEE_SIGNATURE_at_localhost.localdomain.invalid)
Date: 10/05/05


Date: Wed, 5 Oct 2005 14:38:06 +0000 (UTC)

In article <Pine.LNX.4.62.0510051133440.6877@amy>,
Michael <quadfour@iinet.net.au> wrote:
:On Tue, 4 Oct 2005, Robert Nichols wrote:
:>
:> You are aware that only the first packet of a connection is processed in
:> the nat table, right? The rest will automatically get whatever action
:> was taken on the first packet, but wont be seen by any rule in the nat
:> table.
:
:Actually I wasn't aware of this despite seeing this with what was logged.
::)
:
:Thank you, I truly am a n00b

I highly recommend Oskar Andreasson's excellent _IPtables_Tutorial_,
available in several formats from
http://iptables-tutorial.frozentux.net/ .

-- 
Bob Nichols         AT comcast.net I am "RNichols42"


Relevant Pages

  • packet showing up on port 0 when I telnet to port 80?
    ... I am trying to do a reversible NAT for several thousands of ports to ... Why do we have a packet showing up on port 0 when I telnet to port 80? ... permit tcp any range 60000 64999 any log ... When coming from inside, the nat works, and the first packet shows the ...
    (comp.dcom.sys.cisco)
  • Re: Solaris slow in rejecting connections to idle ports
    ... > According to tcpdump, Solaris does not always reply to the first packet ... > trying to open the connection. ...
    (comp.unix.solaris)
  • Re: Client doesnt drop failed source
    ... keep alives if there is no natural traffic in one direction. ... the first packet towards the side that has forgotten the connection will ... (and/or kill the oldest one if you have too many) ...
    (comp.protocols.time.ntp)
  • Another Iptables Filtering Rules Question
    ... > A) That first rule will allow the first packet in the TCP connection ... any way to peek at an incomming connection, and tell the system to toss it ... is there any way to delay any responce (faking the connection to ...
    (comp.os.linux.security)
  • Re: CONFIG_IP_ROUTE_FWMARK not working in Debian !
    ... but I think you're marking only the first packet of the ... connection. ... Homepage: http://geocities.com/arhuaco The first principle is that you must not fool yourself and you are the easiest person to fool. ...
    (Debian-User)