Herbert Xu wrote:
Couldn't we feed the TCP RST packets with foreign sources through the FORWARD table? We're lying to the routing system already by telling it that the packet is forwarded. So I don't see anything wrong with lying to netfilter as well :)
Forwarded packets can't have any NAT manips in LOCAL_OUT, so it should work. I'm not sure about it though because it would be the only place where packets just appear in FORWARD, usually all packets enters through PRE_ROUTING or LOCAL_OUT. Regards Patrick - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Herbert Xu <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- References:
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Herbert Xu <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Patrick McHardy <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Herbert Xu <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Patrick McHardy <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Herbert Xu <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Patrick McHardy <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Herbert Xu <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Patrick McHardy <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- From: Herbert Xu <[email protected]>
- Re: Re-routing packets via netfilter (ip_rt_bug)
- Prev by Date: Re: [BUG] 2.6.12-rc3: unkillable java process in TASK_RUNNING on AMD64
- Next by Date: Re: Re-routing packets via netfilter (ip_rt_bug)
- Previous by thread: Re: Re-routing packets via netfilter (ip_rt_bug)
- Next by thread: Re: Re-routing packets via netfilter (ip_rt_bug)
- Index(es):