Re: snat in PREROUTING chain?
"Stephen M. Rumble" <stephen.rumble-H217xnMUJC0sA/[email protected]> Fri, 27 Apr 2007 23:32:08 -0400
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I went ahead and enabled snat rules in PREROUTING and dnat rules in POSTROUTING by simply including the NF_BR_PRE_ROUTING and NF_BR_POST_ROUTING bits in the userland (extensions/ebt_nat.c lines 151 and 168) and kernel check routines (net/bridge/netfilter/ebt_dnat.c:46 and ebt_snat.c:66). This appears to work fine for my purposes. Kudos on the flexible design! I'd still be interested to know why they're not permitted by default. I suppose in most instances such functionality wouldn't be necessary/useful, but Xen's virtual interfaces make for sort of an inversion of the expected behaviour. Regards, Steve ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/