<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>iptables | User</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/iptables/user/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>23 Nov  2009 15:14:21 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | iptables | User</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/iptables/user/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Old lists are disabled as of now</title>
<description>gmane has picked up the new lists, marc.info probably also (if not it will soon), so effective immediately, I&amp;#039;m disabling subscriptions and postings t</description>
<pubDate>20 Sep  2007 03:51:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69119</link>
</item><item>
<title>Re: Port-based routing with OpenVPN</title>
<description>Hi, and thank you for answering despite the fact i forgot to set a subject :) &amp;gt; Was this trace captured on interface tun0 ? yes &amp;gt; What is the addre</description>
<pubDate>19 Sep  2007 14:21:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69117</link>
</item><item>
<title>Re: Communication between internal hosts, using external addresses</title>
<description>&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;quot;BW&amp;quot; == Bryan Wright &amp;lt;bryan@virginia.edu&amp;gt; writes: BW&amp;gt;   Unfortunately, it doesn&amp;#039;t. Watching with wireshark, it BW&amp;gt; appears that the hosts fa</description>
<pubDate>18 Sep  2007 13:46:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69109</link>
</item><item>
<title>Communication between internal hosts, using external addresses</title>
<description>Hi folks,    This is one of those problems where the best solution may just be &amp;quot;don&amp;#039;t do that&amp;quot;, but here&amp;#039;s my question for what it&amp;#039;s worth:    I</description>
<pubDate>18 Sep  2007 09:28:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69108</link>
</item><item>
<title>Re: [nf-failover] [REMINDER]: netfilter list moved to kernel.org</title>
<description>Rob Sterenborg wrote: &amp;gt;&amp;gt;&amp;gt;&amp;gt;Just a reminder, the netfilter and netfilter-devel lists have &amp;gt;&amp;gt;&amp;gt;&amp;gt;moved to kernel.org, you can subscribe to the new lists at</description>
<pubDate>18 Sep  2007 08:48:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69106</link>
</item><item>
<title>RE: [REMINDER]: netfilter list moved to kernel.org</title>
<description>&amp;gt;&amp;gt;&amp;gt; Just a reminder, the netfilter and netfilter-devel lists have &amp;gt;&amp;gt;&amp;gt; moved to kernel.org, you can subscribe to the new lists at &amp;gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; http://vger.k</description>
<pubDate>18 Sep  2007 08:30:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69105</link>
</item><item>
<title>Re: [REMINDER]: netfilter list moved to kernel.org</title>
<description>Rob Sterenborg wrote: &amp;gt; netfilter-bounces@lists.netfilter.org wrote: &amp;gt; &amp;gt;&amp;gt;Just a reminder, the netfilter and netfilter-devel lists have &amp;gt;&amp;gt;moved to ker</description>
<pubDate>18 Sep  2007 08:04:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69107</link>
</item><item>
<title>RE: [REMINDER]: netfilter list moved to kernel.org</title>
<description>netfilter-bounces@lists.netfilter.org wrote: &amp;gt; Just a reminder, the netfilter and netfilter-devel lists have &amp;gt; moved to kernel.org, you can subscribe</description>
<pubDate>18 Sep  2007 05:34:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69100</link>
</item><item>
<title>DNAT and ICMP</title>
<description>Hi, I am working with SNAT and DNAT rules. When I send a packet {[IP1]} out it goes through the SNAT rules and source field in ip header gets changed</description>
<pubDate>18 Sep  2007 04:47:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69099</link>
</item><item>
<title>[REMINDER]: netfilter list moved to kernel.org</title>
<description>Just a reminder, the netfilter and netfilter-devel lists have moved to kernel.org, you can subscribe to the new lists at http://vger.kernel.org/vger-</description>
<pubDate>18 Sep  2007 04:35:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69097</link>
</item><item>
<title>Kernel crash. Are ipt_recent and ipt_conntrack culprit?</title>
<description>I run RHEL3 with kernel 2.4.21-32.0.1.ELsmp. Yesterday morning I started to play with iptables on this server and yesterday evening I had kernel crash</description>
<pubDate>17 Sep  2007 03:39:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69076</link>
</item><item>
<title>unexpected outgoing ACK</title>
<description>This is on a machine sitting behind another firewall. It runs debian, with debian linux-image-2.6.18-5-686 2.6.18.dfsg.1-13etch2. Once in a while, w</description>
<pubDate>16 Sep  2007 16:38:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69073</link>
</item><item>
<title>Re: Port-based routing with OpenVPN</title>
<description>Hello, Mario Hülsegge a écrit : &amp;gt; &amp;gt; i am trying to set up routing of all outgoing http-requests on my &amp;gt; workstation through my openvpn gateway (tun</description>
<pubDate>16 Sep  2007 04:05:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69070</link>
</item><item>
<title>[no subject]</title>
<description>hi, i am trying to set up routing of all outgoing http-requests on my workstation through my openvpn gateway (tun0). the web told me to do it: ipta</description>
<pubDate>15 Sep  2007 16:15:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69069</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>&amp;gt; Hi!: &amp;gt; &amp;gt; I tried to find a photo to put the names but I didn&amp;#039;t find any photo to edit &amp;gt; ... &amp;gt; &amp;gt; Jorge DÃ¡vila. &amp;gt; http://nfws.inl.fr/en/wp-content/u</description>
<pubDate>15 Sep  2007 10:46:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69067</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>On Sat, Sep 15, 2007 at 11:03:08AM -0600, Jorge Davila wrote: &amp;gt; Hi!: &amp;gt; &amp;gt; I tried to find a photo to put the names but I didn&amp;#039;t find any photo to &amp;gt; ed</description>
<pubDate>15 Sep  2007 10:40:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69060</link>
</item><item>
<title>Re: Question about http://ipset.netfilter.org/ site</title>
<description>Re! Ok, sorry to bother you, I missed the email announcement of the migration. :) Best wishes, René. --  )\._.,--....,&amp;#039;``.   Let GNU/Linux wor</description>
<pubDate>15 Sep  2007 10:38:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69064</link>
</item><item>
<title>Question about http://ipset.netfilter.org/ site</title>
<description>Hello! It seems there&amp;#039;s something wrong with the http://ipset.netfilter.org/ site. I get an 403 Forbidden when trying to get it. Has the project move</description>
<pubDate>15 Sep  2007 10:25:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69068</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>Hi!: I tried to find a photo to put the names but I didn&amp;#039;t find any photo to edit ... Jorge Dávila.  On Sat, 15 Sep 2007 11:37:45 +0200  Harald W</description>
<pubDate>15 Sep  2007 10:03:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69066</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>From: Patrick McHardy &amp;lt;kaber@trash.net&amp;gt; Date: Sat, 15 Sep 2007 12:40:13 +0200 &amp;gt; Soyoung Park should also be on there next to Dave, but she seems to b</description>
<pubDate>15 Sep  2007 09:13:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69078</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>Harald Welte wrote: &amp;gt; I don&amp;#039;t have an annotated photo, but maybe somebody wants to make one &amp;gt; using the following data: &amp;gt; &amp;gt; (all from left to right)</description>
<pubDate>15 Sep  2007 03:40:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69054</link>
</item><item>
<title>netfilter workshop group photo annotations</title>
<description>On Wed, Sep 12, 2007 at 08:30:48PM +0200, Jan Engelhardt wrote: &amp;gt; &amp;gt; On Sep 12 2007 12:36, Patrick McHardy wrote: &amp;gt; &amp;gt; The netfilter and netfilter-deve</description>
<pubDate>15 Sep  2007 02:37:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69056</link>
</item><item>
<title>Re: INPUT and uid-owner</title>
<description>Sofy: The uid-owner match is not longer supported. Jorge Dávila. On Thu, 13 Sep 2007 15:20:18 +0300  &amp;quot;SoFy DeNiro&amp;quot; &amp;lt;sofy.guru@gmail.com&amp;gt; wrote: &amp;gt;</description>
<pubDate>13 Sep  2007 11:34:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69051</link>
</item><item>
<title>Re: INPUT and uid-owner</title>
<description>sorry, this is not the correct link, please use: http://iptables-tutorial.frozentux.net/iptables-tutorial.html  Stefan Lamby schrieb: &amp;gt; there is some</description>
<pubDate>13 Sep  2007 05:49:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69046</link>
</item><item>
<title>Re: INPUT and uid-owner</title>
<description>there is something that could fit your needs: go to http://iptables-tutorial.frozentux.net/iptables-tutorial.htm and search for owner match. Hope thi</description>
<pubDate>13 Sep  2007 05:38:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69045</link>
</item><item>
<title>INPUT and uid-owner</title>
<description>Hi, Is there&amp;#039;s anyway to use INPUT chain with uid-owner ? something like that : iptables -A INPUT -p tcp -mowner --uid-owner root --dport 80 -j DRO</description>
<pubDate>13 Sep  2007 05:20:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69044</link>
</item><item>
<title>Re: Examples of using IPTABLES on linux</title>
<description>On Thu, 13 Sep 2007 12:40:02 +0100, Danesh Qureshi wrote &amp;gt; Are there any examples of using IPTABLES with explanations of each &amp;gt; command on Linux? Se</description>
<pubDate>13 Sep  2007 05:07:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69043</link>
</item><item>
<title>Examples of using IPTABLES on linux</title>
<description>Hi, Are there any examples of using IPTABLES with explanations of each command on Linux? Regards, Dan</description>
<pubDate>13 Sep  2007 04:40:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69042</link>
</item><item>
<title>Re: [ANNOUNCE]: netfilter-devel and netfilter list moving to kernel.org</title>
<description>On Sep 12 2007 12:36, Patrick McHardy wrote: &amp;gt; The netfilter and netfilter-devel mailinglists are moving &amp;gt; to kernel.org, you can subscribe to the new</description>
<pubDate>12 Sep  2007 11:30:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69039</link>
</item><item>
<title>[ADMINISTRATIVE] netfilter.org downtime</title>
<description>Hi! There will be an administrative downtime of pracitcally all netfilter.org services during the next couple of days (thursday/friday). I don&amp;#039;t real</description>
<pubDate>12 Sep  2007 08:37:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69037</link>
</item><item>
<title>Re: FWDing packets from a physical interface to a virtual interface</title>
<description>So maybe you&amp;#039;ll have to some bridging stuff and not netfilter/iptables ones ....   iptables/netfilter deals basically with Layer 3 (IP) packets an</description>
<pubDate>12 Sep  2007 04:45:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69034</link>
</item><item>
<title>Re: FWDing packets from a physical interface to a virtual interface</title>
<description>Thanks Jorge, I&amp;#039;m not using any specific VPN solution, Me and my colleagues are developing a secure VPN solution based on kernel TUN/TAP driver. Sinc</description>
<pubDate>12 Sep  2007 04:32:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69033</link>
</item><item>
<title>[ANNOUNCE]: netfilter-devel and netfilter list moving to kernel.org</title>
<description>The netfilter and netfilter-devel mailinglists are moving to kernel.org, you can subscribe to the new lists at: http://vger.kernel.org/vger-lists.htm</description>
<pubDate>12 Sep  2007 03:36:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69030</link>
</item><item>
<title>Re: FWDing packets from a physical interface to a virtual interface</title>
<description>Arash: AFAIK, you must open a path in the firewall to the vpn daemon (port/protocol) and the daemon will be in charge of administering the traffic</description>
<pubDate>11 Sep  2007 18:40:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69028</link>
</item><item>
<title>FWDing packets from a physical interface to a virtual interface</title>
<description>Hi, :) Here is the situation: I have a machine with 2 NICs, assume eth0 (192.168.0.10) connected to my LAN, and eth1 (192.168.0.20) connected to Int</description>
<pubDate>11 Sep  2007 15:36:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69027</link>
</item><item>
<title>Connection freeze while downloading</title>
<description>Hi. I have problem in following scenario: 3 routers A, B, C: router A: eth0--&amp;gt; DSL ( public IP ) eth1 --&amp;gt; 192.168.0.1 ( local network ) routing t</description>
<pubDate>11 Sep  2007 14:54:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69026</link>
</item><item>
<title>Re: How to combine a few addresses?</title>
<description>Vitaly wrote: &amp;gt; --- Martijn Lievaart &amp;lt;m@rtij.nl&amp;gt; wrote: &amp;gt; &amp;gt;  &amp;gt;&amp;gt; Vitaly wrote: &amp;gt;&amp;gt;   &amp;gt;&amp;gt;&amp;gt; How I can combine a few addresses in one rule? For &amp;gt;&amp;gt;&amp;gt; exa</description>
<pubDate>11 Sep  2007 10:50:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69025</link>
</item><item>
<title>modify source IP of local processed packets before routing</title>
<description>Hi, My goal is to modify the source IP address of local processed packets but it has to be done before any routing (so the packet will be directed</description>
<pubDate>11 Sep  2007 08:31:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69024</link>
</item><item>
<title>Re: How to combine a few addresses?</title>
<description>--- Martijn Lievaart &amp;lt;m@rtij.nl&amp;gt; wrote: &amp;gt; Vitaly wrote: &amp;gt; &amp;gt; How I can combine a few addresses in one rule? For &amp;gt; &amp;gt; example, I&amp;#039;d like to add two IPs 1</description>
<pubDate>11 Sep  2007 05:27:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69023</link>
</item><item>
<title>Re: How to combine a few addresses?</title>
<description>Vitaly wrote: &amp;gt; How I can combine a few addresses in one rule? For &amp;gt; example, I&amp;#039;d like to add two IPs 10.10.10.1 and &amp;gt; 10.10.10.2 to the same rule. &amp;gt;</description>
<pubDate>11 Sep  2007 05:01:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69022</link>
</item><item>
<title>How to combine a few addresses?</title>
<description>How I can combine a few addresses in one rule? For example, I&amp;#039;d like to add two IPs 10.10.10.1 and 10.10.10.2 to the same rule.     ______________</description>
<pubDate>11 Sep  2007 04:52:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69021</link>
</item><item>
<title>broadcasting over ipsec vpn..?</title>
<description>Hello everybody, i need to know the possibilities of iptables for the following setup.. My gateway security device has three interfaces Device-1 --</description>
<pubDate>11 Sep  2007 04:50:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69020</link>
</item><item>
<title>Re: Route packets from an interface to another</title>
<description>On 09/10/07 07:18, vinod K D wrote: &amp;gt; My gateway has two network interfaces: eth0 &amp;amp; eth1. &amp;gt; &amp;gt; eth0 (192.168.1.1) is connected to public network and e</description>
<pubDate>10 Sep  2007 08:23:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69016</link>
</item><item>
<title>Connection Marking and source routing woes</title>
<description>Hi all, I just introduced a new 10Mbit/s line into my network, and I&amp;#039;m severely rusty on iptables and experiencing some trouble setting up my rules p</description>
<pubDate>10 Sep  2007 08:17:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69015</link>
</item><item>
<title>Route packets from an interface to another</title>
<description>First of all, I&amp;#039;ll explain my network setup.  My gateway has two network interfaces: eth0 &amp;amp; eth1.   eth0 (192.168.1.1) is connected to public netw</description>
<pubDate>10 Sep  2007 05:18:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69014</link>
</item><item>
<title>Re: Firewall setting</title>
<description>update: Related to ftp http://www.kalamazoolinux.org/presentations/20010417/conntrack.html at very end of article there is additional explanation re</description>
<pubDate>08 Sep  2007 10:34:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69006</link>
</item><item>
<title>Re: Firewall setting</title>
<description>Dear Edward, it is not very clear what you want to make. If you want to allow ssh connections to specific host AFAIK the below can help #!/bin/bash</description>
<pubDate>08 Sep  2007 10:25:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69005</link>
</item><item>
<title>Firewall setting</title>
<description>Dear All, For the Firewall setting, how can we use the ftp and ssh service ? For file 1 : #!/bin/bash modprobe ip_tables modprobe ip_nat_ftp modpr</description>
<pubDate>08 Sep  2007 04:56:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69001</link>
</item><item>
<title>Re: Cryptic ulogd 2.0.0beta1 error message</title>
<description>Hi, Le samedi 08 septembre 2007 à 00:10 +0200, Christoph J. Thompson a écrit : &amp;gt; On Fri, 07 Sep 2007 23:51:16 +0200 &amp;gt; Eric Leblond &amp;lt;eric@inl.fr&amp;gt; wrot</description>
<pubDate>07 Sep  2007 15:50:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68999</link>
</item><item>
<title>Re: Cryptic ulogd 2.0.0beta1 error message</title>
<description>On Fri, 07 Sep 2007 23:51:16 +0200 Eric Leblond &amp;lt;eric@inl.fr&amp;gt; wrote: &amp;gt; Use svn version, it should fix the bug : &amp;gt; https://svn.netfilter.org/netfilter/</description>
<pubDate>07 Sep  2007 15:10:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68998</link>
</item><item>
<title>Re: Cryptic ulogd 2.0.0beta1 error message</title>
<description>Hi, Le vendredi 07 septembre 2007 à 23:34 +0200, Christoph J. Thompson a écrit : &amp;gt; Greetings, &amp;gt; &amp;gt; I&amp;#039;m trying to get ulogd 2.0.0beta1 to work but eac</description>
<pubDate>07 Sep  2007 14:51:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68997</link>
</item><item>
<title>Re: Cryptic ulogd 2.0.0beta1 error message</title>
<description>Hi, Le vendredi 07 septembre 2007 à 23:34 +0200, Christoph J. Thompson a écrit : &amp;gt; Greetings, &amp;gt; &amp;gt; I&amp;#039;m trying to get ulogd 2.0.0beta1 to work but eac</description>
<pubDate>07 Sep  2007 14:50:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68996</link>
</item><item>
<title>Cryptic ulogd 2.0.0beta1 error message</title>
<description>Greetings, I&amp;#039;m trying to get ulogd 2.0.0beta1 to work but each time I start the daemon I get this in my log file: Fri Sep 7 22:21:45 2007 &amp;lt;5&amp;gt; ulogd</description>
<pubDate>07 Sep  2007 14:34:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68995</link>
</item><item>
<title>Re: ipt_MASQUERADE issue</title>
<description>On Thu, 06 Sep 2007 18:38:06 +0200, Pascal Hambourg &amp;lt;pascal.mail@plouf.fr.eu.org&amp;gt; wrote: &amp;gt; stevesz@enternet.hu a Ã©crit : &amp;gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;I am not sure I under</description>
<pubDate>07 Sep  2007 00:51:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68986</link>
</item><item>
<title>Re: 3 ethernet card package transfer</title>
<description>&amp;gt; In my machine i have 3 ethernet cards: eth0, eth1 and eth2 &amp;gt; &amp;gt; eth0 had 192.168.1.20, eth1 192.168.1.1 and eth2 had 10.0.0.1 ip. eth1 &amp;gt; and eth2 are</description>
<pubDate>07 Sep  2007 00:09:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68985</link>
</item><item>
<title>Initialization of local variable in a iptables datastructure</title>
<description>Hi I have introduced a variable in xt_counters data structure of type uint_64t to be used as a counter in ipt_entry data structure. I have installed</description>
<pubDate>06 Sep  2007 19:50:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68984</link>
</item><item>
<title>3 ethernet card package transfer</title>
<description>Hi, In my machine i have 3 ethernet cards: eth0, eth1 and eth2 eth0 had 192.168.1.20, eth1 192.168.1.1 and eth2 had 10.0.0.1 ip. eth1 and eth2 are</description>
<pubDate>06 Sep  2007 13:08:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68983</link>
</item><item>
<title>Re: ipt_MASQUERADE issue</title>
<description>stevesz@enternet.hu a écrit : &amp;gt;&amp;gt; &amp;gt;&amp;gt;I am not sure I understand what the problem is. When the IP address &amp;gt;&amp;gt;changes, any existing connections that were</description>
<pubDate>06 Sep  2007 09:38:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68982</link>
</item><item>
<title>Re: ipt_MASQUERADE issue</title>
<description>On Thu, 06 Sep 2007 16:48:15 +0200, Pascal Hambourg &amp;lt;pascal.mail@plouf.fr.eu.org&amp;gt; wrote: &amp;gt; Hello, &amp;gt; &amp;gt; stevesz@enternet.hu a Ã©crit : &amp;gt;&amp;gt; &amp;gt;&amp;gt; I&amp;#039;m using</description>
<pubDate>06 Sep  2007 08:58:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68981</link>
</item><item>
<title>Re: Iptables and bridging</title>
<description>Hello, Ludovic MARCILLY a écrit : &amp;gt; &amp;gt; i have a linux box with three ethernet card. I want to bridge eth0 &amp;gt; with eth2 and to have eth1 like a DMZ. &amp;gt;</description>
<pubDate>06 Sep  2007 08:18:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68979</link>
</item><item>
<title>Re: ipt_MASQUERADE issue</title>
<description>Hello, stevesz@enternet.hu a écrit : &amp;gt; &amp;gt; I&amp;#039;m using kernel v. 2.6.22.1, iptables v. 1.3.8. &amp;gt; I have an ADSL connection with dynamic IP. &amp;gt; I use ipp2p</description>
<pubDate>06 Sep  2007 07:48:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68978</link>
</item><item>
<title>ipt_MASQUERADE issue</title>
<description>Hi All, I&amp;#039;m using kernel v. 2.6.22.1, iptables v. 1.3.8. I have an ADSL connection with dynamic IP. I use ipp2p to indentify and CONNMARK to mark p2p</description>
<pubDate>06 Sep  2007 06:35:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68977</link>
</item><item>
<title>Remapping networks</title>
<description>Hi, I am currently setting up a server which connects an internal LAN to multiple other LANs via VPNs (i.e. my server acts as VPN client, connecting</description>
<pubDate>05 Sep  2007 11:04:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68955</link>
</item><item>
<title>Iptables and bridging</title>
<description>Hi all, i have a linux box with three ethernet card. I want to bridge eth0 with eth2 and to have eth1 like a DMZ. Before, i was using linux-2.4.27 w</description>
<pubDate>05 Sep  2007 09:00:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68953</link>
</item><item>
<title>Re: IPSET iptree problem</title>
<description>On Mon, 27 Aug 2007, Sami Farin wrote: &amp;gt; Your mask_to_bits function results into infinite loop if called &amp;gt; with parameter 1, for example. &amp;gt; &amp;gt; If you</description>
<pubDate>05 Sep  2007 03:39:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68947</link>
</item><item>
<title>Re: problem on iptables</title>
<description>Well, the option is in Network Configuration ... and yes, you need recompile after ... On Tue, 4 Sep 2007 15:45:01 -0400  &amp;quot;Peng Yang&amp;quot; &amp;lt;pey204@gmail</description>
<pubDate>04 Sep  2007 14:20:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68942</link>
</item><item>
<title>Re: problem on iptables</title>
<description>Hi Jorge, How to turn on this configuration? I am using kernel 2.6.20.11. Do I need to recompile the kernel after turning on the configuration? than</description>
<pubDate>04 Sep  2007 12:45:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68941</link>
</item><item>
<title>Re: problem on iptables</title>
<description>You don&amp;#039;t need any patch to put to work netfilter/iptables. I&amp;#039;m pretty sure that is disabled in the kernel configuration. Jorge. On Tue, 4 Sep 2007</description>
<pubDate>04 Sep  2007 12:11:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68939</link>
</item><item>
<title>problem on iptables</title>
<description>Hi, In our current kernel, iptables doesn&amp;#039;t work due to the error &amp;quot;can&amp;#039;t initialize iptables table `filter&amp;#039;&amp;quot;. I suspect that the netfilter is not turn</description>
<pubDate>04 Sep  2007 11:48:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68938</link>
</item><item>
<title>RE: [nf-failover] Re: conntrack and conntrackd</title>
<description>&amp;gt; The appropriate patches need to go into kernel for this. I sent a patch &amp;gt; for this, look for: &amp;gt; &amp;gt; [PATCH 7/8][CTNETLINK] send conntrack events on c</description>
<pubDate>04 Sep  2007 03:31:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68934</link>
</item><item>
<title>[Announce] Nulog 2.0-alpha1, log analysis tool for Netfilter</title>
<description>Hi, INL Devel Team is proud to announce the availability of the first preview of Nulog2. Nulog2 is a complete rewrite of Nulog the historical filter</description>
<pubDate>03 Sep  2007 14:34:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68930</link>
</item><item>
<title>Re: Debugging network problems</title>
<description>Some more info: One of my major issues is during svn operations. In the middle of an operation such svn up, the update starts ok, then at some point,</description>
<pubDate>02 Sep  2007 19:15:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68908</link>
</item><item>
<title>RE: Firewall Issues</title>
<description>Mike,  You may also need to put an entry on the output in the NAT table as well. Here is what I have had to do in the past, to make things work. Ple</description>
<pubDate>02 Sep  2007 09:05:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68906</link>
</item><item>
<title>Re: conntrack and conntrackd</title>
<description>Filka Michal wrote: &amp;gt; I&amp;#039;ve problem when using conntrack and conntrackd. &amp;gt; &amp;gt; I tried to create a record using conntrack. But, I didn&amp;#039;t see the record</description>
<pubDate>02 Sep  2007 02:04:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68896</link>
</item><item>
<title>Re: conntrack entries - editing</title>
<description>Július Bem¹ wrote: &amp;gt; Hello, &amp;gt; &amp;gt; Is there any way how to edit/delete/create entries in the conntrack table ? http://people.netfilter.org/pablo/conntr</description>
<pubDate>02 Sep  2007 02:00:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68895</link>
</item><item>
<title>Re: Debugging network problems</title>
<description>Thank you, Martijn, My reply inline.  &amp;gt; &amp;gt; Generally, I can connect to the outside world, and the outside world can &amp;gt; &amp;gt; connect to me. By this, I mea</description>
<pubDate>31 Aug  2007 00:43:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68876</link>
</item><item>
<title>Re: Debugging network problems</title>
<description>David Leangen wrote: &amp;gt; Hello! &amp;gt; &amp;gt; My network was just changed from a vanilla ADSL connection to direct &amp;gt; ftth. There is now a network connector with a</description>
<pubDate>30 Aug  2007 22:33:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68875</link>
</item><item>
<title>Setting skb-&amp;gt;len</title>
<description>Hi netfilter list, This is my first post to this list, so if this question is better handled by a different list, or offtopic, please kindly inform</description>
<pubDate>30 Aug  2007 15:12:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68873</link>
</item><item>
<title>Re: Alternatives to window shaping?</title>
<description>Justin: TCP window scaling is an inherent behaviour of the tcp protocol and the parameter can be tunned. Because you didn&amp;#039;t references the devices</description>
<pubDate>30 Aug  2007 13:56:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68872</link>
</item><item>
<title>RE: iptables: Unknown error 4294967295</title>
<description>&amp;gt; How can I recompile the kernel and not iptables. Simple. They are separate packages (iptables is not the same as netfilter; it&amp;#039;s part of the projec</description>
<pubDate>30 Aug  2007 09:59:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68869</link>
</item><item>
<title>Re: iptables: Unknown error 4294967295</title>
<description>How can I recompile the kernel and not iptables.  KARIM SATTAR escreveu: &amp;gt; Hi &amp;gt; &amp;gt; I am getting the error as mentioned below; the problem arose wh</description>
<pubDate>30 Aug  2007 09:49:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68868</link>
</item><item>
<title>Re: Alternatives to window shaping?</title>
<description>You didn&amp;#039;t explain how you were doing the QoS policy on the line. What you are describing is what is SUPPOSE to happen when your network interface i</description>
<pubDate>30 Aug  2007 08:14:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68867</link>
</item><item>
<title>RE: [nf-failover] conntrack and conntrackd</title>
<description>Hi, I observed that when creating conntrack record using conntrack tool, no event is catched (using conntrack -E). That might be reason why the recor</description>
<pubDate>30 Aug  2007 06:11:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68865</link>
</item><item>
<title>conntrack and conntrackd</title>
<description>Hi, I&amp;#039;ve problem when using conntrack and conntrackd.  I tried to create a record using conntrack. But, I didn&amp;#039;t see the record in conntrackd cache</description>
<pubDate>30 Aug  2007 04:41:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68864</link>
</item><item>
<title>Re: iptables: Unknown error 4294967295</title>
<description>KARIM SATTAR escreveu: &amp;gt; Hi &amp;gt; &amp;gt; I am getting the error as mentioned below; the problem arose when I  &amp;gt; have changed the data structure of the ipt_ent</description>
<pubDate>30 Aug  2007 03:58:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68863</link>
</item><item>
<title>Alternatives to window shaping?</title>
<description>I have posted this before under another thread, but did not get many replies. So I thought I would post it under a more appropriate subject. OK, so</description>
<pubDate>30 Aug  2007 03:45:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68862</link>
</item><item>
<title>iptables: Unknown error 4294967295</title>
<description>Hi I am getting the error as mentioned below; the problem arose when I  have changed the data structure of the ipt_entry which stores the rules  an</description>
<pubDate>30 Aug  2007 02:42:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68859</link>
</item><item>
<title>Re: Netfilter_queue test program question</title>
<description>&amp;gt; However, in any case when I run the compiled nfq_test, the program &amp;gt; seems to do nothing after setting the packet copy mode. So it seems &amp;gt; to me as</description>
<pubDate>29 Aug  2007 10:57:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68845</link>
</item><item>
<title>Re: match time &amp;amp; kernel 2.6.22.5</title>
<description>Hi Andrew, Thank for our help, now the new kerl is build with iptables time match. This is the first time I add match for iptables and this procedrue</description>
<pubDate>29 Aug  2007 09:30:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68840</link>
</item><item>
<title>Re: Netfilter_queue test program question</title>
<description>On 8/29/07, Gáspár Lajos &amp;lt;swifty@freemail.hu&amp;gt; wrote: &amp;gt; Andy Cristina írta: &amp;gt; &amp;gt; I&amp;#039;ve been attempting to play with netfilter_queue to see how effective</description>
<pubDate>29 Aug  2007 06:21:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68821</link>
</item><item>
<title>Debugging network problems</title>
<description>Hello! My network was just changed from a vanilla ADSL connection to direct ftth. There is now a network connector with a 100MB/s entry, which gets</description>
<pubDate>29 Aug  2007 03:33:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68816</link>
</item><item>
<title>Re: Netfilter_queue test program question</title>
<description>Andy Cristina írta: &amp;gt; I&amp;#039;ve been attempting to play with netfilter_queue to see how effective &amp;gt; a certain similarity hashing technique would work for i</description>
<pubDate>29 Aug  2007 02:42:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68815</link>
</item><item>
<title>Netfilter_queue test program question</title>
<description>I&amp;#039;ve been attempting to play with netfilter_queue to see how effective a certain similarity hashing technique would work for identifying parts of docu</description>
<pubDate>29 Aug  2007 01:13:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68813</link>
</item><item>
<title>Re: Implement single firewall login for access to all ports on LAN?</title>
<description>On 8/28/2007 11:59 PM, Grant Taylor wrote: &amp;gt; - Use the comment match extension to put a label in rules. The comment match extension will allow you t</description>
<pubDate>28 Aug  2007 22:04:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68811</link>
</item><item>
<title>Re: Implement single firewall login for access to all ports on LAN?</title>
<description>On 8/27/2007 9:45 AM, quesera2 wrote: &amp;gt; My thoughts are to have a strong challenge/response login from a &amp;gt; client to the firewall. This could be done</description>
<pubDate>28 Aug  2007 21:59:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68810</link>
</item><item>
<title>Re: [ANNOUNCE] ipset 2.3.0 released</title>
<description>On Tue, 28 Aug 2007, Jan Engelhardt wrote: &amp;gt;&amp;gt; - endiannes bug in iptree type fixed (spotted by Jan Engelhardt) &amp;gt; &amp;gt; Was it really a bug? We were not s</description>
<pubDate>28 Aug  2007 05:34:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68805</link>
</item><item>
<title>Re: [ANNOUNCE] ipset 2.3.0 released</title>
<description>On Aug 28 2007 14:19, Jan Engelhardt wrote: &amp;gt;&amp;gt; http://ipset.netfilter.org/ &amp;gt; &amp;gt;I&amp;#039;m kinda missing the kernel files. There is iptables, ipset-2.3.0, and</description>
<pubDate>28 Aug  2007 05:19:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68905</link>
</item><item>
<title>Re: [ANNOUNCE] ipset 2.3.0 released</title>
<description>On Aug 28 2007 13:05, Jozsef Kadlecsik wrote: &amp;gt; &amp;gt; I&amp;#039;m happy to announce the new ipset release. The main changes are &amp;gt; &amp;gt; - jiffies rollover bug in iptr</description>
<pubDate>28 Aug  2007 05:19:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68904</link>
</item><item>
<title>[ANNOUNCE] ipset 2.3.0 released</title>
<description>Hi, I&amp;#039;m happy to announce the new ipset release. The main changes are  - jiffies rollover bug in iptree type fixed (reported by Lukasz Nierycho</description>
<pubDate>28 Aug  2007 04:05:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68801</link>
</item><item>
<title>Re: Change ip_conntrack_sip default port</title>
<description>On Tue, 28 Aug 2007, Sebastien VECTEN wrote: &amp;gt; You are right, indeed I have just tested and that doesn&amp;#039;t work, it&amp;#039;s &amp;gt; just to follow traffic bound t</description>
<pubDate>28 Aug  2007 01:49:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68799</link>
</item>
</channel>
</rss>
