<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>iptables | User</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/iptables/user/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>25 Nov  2009 16:34:11 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | iptables | User</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/iptables/user/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Old lists are disabled as of now</title>
<description>gmane has picked up the new lists, marc.info probably also (if not it will soon), so effective immediately, I&amp;#039;m disabling subscriptions and postings t</description>
<pubDate>20 Sep  2007 03:51:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69119</link>
</item><item>
<title>Communication between internal hosts, using external addresses</title>
<description>Hi folks,    This is one of those problems where the best solution may just be &amp;quot;don&amp;#039;t do that&amp;quot;, but here&amp;#039;s my question for what it&amp;#039;s worth:    I</description>
<pubDate>18 Sep  2007 09:28:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69108</link>
</item><item>
<title>DNAT and ICMP</title>
<description>Hi, I am working with SNAT and DNAT rules. When I send a packet {[IP1]} out it goes through the SNAT rules and source field in ip header gets changed</description>
<pubDate>18 Sep  2007 04:47:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69099</link>
</item><item>
<title>[REMINDER]: netfilter list moved to kernel.org</title>
<description>Just a reminder, the netfilter and netfilter-devel lists have moved to kernel.org, you can subscribe to the new lists at http://vger.kernel.org/vger-</description>
<pubDate>18 Sep  2007 04:35:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69097</link>
</item><item>
<title>Kernel crash. Are ipt_recent and ipt_conntrack culprit?</title>
<description>I run RHEL3 with kernel 2.4.21-32.0.1.ELsmp. Yesterday morning I started to play with iptables on this server and yesterday evening I had kernel crash</description>
<pubDate>17 Sep  2007 03:39:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69076</link>
</item><item>
<title>unexpected outgoing ACK</title>
<description>This is on a machine sitting behind another firewall. It runs debian, with debian linux-image-2.6.18-5-686 2.6.18.dfsg.1-13etch2. Once in a while, w</description>
<pubDate>16 Sep  2007 16:38:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69073</link>
</item><item>
<title>[no subject]</title>
<description>hi, i am trying to set up routing of all outgoing http-requests on my workstation through my openvpn gateway (tun0). the web told me to do it: ipta</description>
<pubDate>15 Sep  2007 16:15:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69069</link>
</item><item>
<title>Re: Question about http://ipset.netfilter.org/ site</title>
<description>Re! Ok, sorry to bother you, I missed the email announcement of the migration. :) Best wishes, René. --  )\._.,--....,&amp;#039;``.   Let GNU/Linux wor</description>
<pubDate>15 Sep  2007 10:38:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69064</link>
</item><item>
<title>Question about http://ipset.netfilter.org/ site</title>
<description>Hello! It seems there&amp;#039;s something wrong with the http://ipset.netfilter.org/ site. I get an 403 Forbidden when trying to get it. Has the project move</description>
<pubDate>15 Sep  2007 10:25:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69068</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>Harald Welte wrote: &amp;gt; I don&amp;#039;t have an annotated photo, but maybe somebody wants to make one &amp;gt; using the following data: &amp;gt; &amp;gt; (all from left to right)</description>
<pubDate>15 Sep  2007 03:40:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69054</link>
</item><item>
<title>netfilter workshop group photo annotations</title>
<description>On Wed, Sep 12, 2007 at 08:30:48PM +0200, Jan Engelhardt wrote: &amp;gt; &amp;gt; On Sep 12 2007 12:36, Patrick McHardy wrote: &amp;gt; &amp;gt; The netfilter and netfilter-deve</description>
<pubDate>15 Sep  2007 02:37:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69056</link>
</item><item>
<title>INPUT and uid-owner</title>
<description>Hi, Is there&amp;#039;s anyway to use INPUT chain with uid-owner ? something like that : iptables -A INPUT -p tcp -mowner --uid-owner root --dport 80 -j DRO</description>
<pubDate>13 Sep  2007 05:20:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69044</link>
</item><item>
<title>Examples of using IPTABLES on linux</title>
<description>Hi, Are there any examples of using IPTABLES with explanations of each command on Linux? Regards, Dan</description>
<pubDate>13 Sep  2007 04:40:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69042</link>
</item><item>
<title>[ADMINISTRATIVE] netfilter.org downtime</title>
<description>Hi! There will be an administrative downtime of pracitcally all netfilter.org services during the next couple of days (thursday/friday). I don&amp;#039;t real</description>
<pubDate>12 Sep  2007 08:37:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69037</link>
</item><item>
<title>[ANNOUNCE]: netfilter-devel and netfilter list moving to kernel.org</title>
<description>The netfilter and netfilter-devel mailinglists are moving to kernel.org, you can subscribe to the new lists at: http://vger.kernel.org/vger-lists.htm</description>
<pubDate>12 Sep  2007 03:36:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69030</link>
</item><item>
<title>FWDing packets from a physical interface to a virtual interface</title>
<description>Hi, :) Here is the situation: I have a machine with 2 NICs, assume eth0 (192.168.0.10) connected to my LAN, and eth1 (192.168.0.20) connected to Int</description>
<pubDate>11 Sep  2007 15:36:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69027</link>
</item><item>
<title>Connection freeze while downloading</title>
<description>Hi. I have problem in following scenario: 3 routers A, B, C: router A: eth0--&amp;gt; DSL ( public IP ) eth1 --&amp;gt; 192.168.0.1 ( local network ) routing t</description>
<pubDate>11 Sep  2007 14:54:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69026</link>
</item><item>
<title>modify source IP of local processed packets before routing</title>
<description>Hi, My goal is to modify the source IP address of local processed packets but it has to be done before any routing (so the packet will be directed</description>
<pubDate>11 Sep  2007 08:31:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69024</link>
</item><item>
<title>How to combine a few addresses?</title>
<description>How I can combine a few addresses in one rule? For example, I&amp;#039;d like to add two IPs 10.10.10.1 and 10.10.10.2 to the same rule.     ______________</description>
<pubDate>11 Sep  2007 04:52:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69021</link>
</item><item>
<title>broadcasting over ipsec vpn..?</title>
<description>Hello everybody, i need to know the possibilities of iptables for the following setup.. My gateway security device has three interfaces Device-1 --</description>
<pubDate>11 Sep  2007 04:50:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69020</link>
</item><item>
<title>Connection Marking and source routing woes</title>
<description>Hi all, I just introduced a new 10Mbit/s line into my network, and I&amp;#039;m severely rusty on iptables and experiencing some trouble setting up my rules p</description>
<pubDate>10 Sep  2007 08:17:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69015</link>
</item><item>
<title>Route packets from an interface to another</title>
<description>First of all, I&amp;#039;ll explain my network setup.  My gateway has two network interfaces: eth0 &amp;amp; eth1.   eth0 (192.168.1.1) is connected to public netw</description>
<pubDate>10 Sep  2007 05:18:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69014</link>
</item><item>
<title>Firewall setting</title>
<description>Dear All, For the Firewall setting, how can we use the ftp and ssh service ? For file 1 : #!/bin/bash modprobe ip_tables modprobe ip_nat_ftp modpr</description>
<pubDate>08 Sep  2007 04:56:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/69001</link>
</item><item>
<title>Cryptic ulogd 2.0.0beta1 error message</title>
<description>Greetings, I&amp;#039;m trying to get ulogd 2.0.0beta1 to work but each time I start the daemon I get this in my log file: Fri Sep 7 22:21:45 2007 &amp;lt;5&amp;gt; ulogd</description>
<pubDate>07 Sep  2007 14:34:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68995</link>
</item><item>
<title>Initialization of local variable in a iptables datastructure</title>
<description>Hi I have introduced a variable in xt_counters data structure of type uint_64t to be used as a counter in ipt_entry data structure. I have installed</description>
<pubDate>06 Sep  2007 19:50:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68984</link>
</item><item>
<title>3 ethernet card package transfer</title>
<description>Hi, In my machine i have 3 ethernet cards: eth0, eth1 and eth2 eth0 had 192.168.1.20, eth1 192.168.1.1 and eth2 had 10.0.0.1 ip. eth1 and eth2 are</description>
<pubDate>06 Sep  2007 13:08:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68983</link>
</item><item>
<title>ipt_MASQUERADE issue</title>
<description>Hi All, I&amp;#039;m using kernel v. 2.6.22.1, iptables v. 1.3.8. I have an ADSL connection with dynamic IP. I use ipp2p to indentify and CONNMARK to mark p2p</description>
<pubDate>06 Sep  2007 06:35:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68977</link>
</item><item>
<title>Remapping networks</title>
<description>Hi, I am currently setting up a server which connects an internal LAN to multiple other LANs via VPNs (i.e. my server acts as VPN client, connecting</description>
<pubDate>05 Sep  2007 11:04:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68955</link>
</item><item>
<title>Iptables and bridging</title>
<description>Hi all, i have a linux box with three ethernet card. I want to bridge eth0 with eth2 and to have eth1 like a DMZ. Before, i was using linux-2.4.27 w</description>
<pubDate>05 Sep  2007 09:00:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68953</link>
</item><item>
<title>problem on iptables</title>
<description>Hi, In our current kernel, iptables doesn&amp;#039;t work due to the error &amp;quot;can&amp;#039;t initialize iptables table `filter&amp;#039;&amp;quot;. I suspect that the netfilter is not turn</description>
<pubDate>04 Sep  2007 11:48:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68938</link>
</item><item>
<title>[Announce] Nulog 2.0-alpha1, log analysis tool for Netfilter</title>
<description>Hi, INL Devel Team is proud to announce the availability of the first preview of Nulog2. Nulog2 is a complete rewrite of Nulog the historical filter</description>
<pubDate>03 Sep  2007 14:34:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68930</link>
</item><item>
<title>Setting skb-&amp;gt;len</title>
<description>Hi netfilter list, This is my first post to this list, so if this question is better handled by a different list, or offtopic, please kindly inform</description>
<pubDate>30 Aug  2007 15:12:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68873</link>
</item><item>
<title>RE: [nf-failover] conntrack and conntrackd</title>
<description>Hi, I observed that when creating conntrack record using conntrack tool, no event is catched (using conntrack -E). That might be reason why the recor</description>
<pubDate>30 Aug  2007 06:11:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68865</link>
</item><item>
<title>conntrack and conntrackd</title>
<description>Hi, I&amp;#039;ve problem when using conntrack and conntrackd.  I tried to create a record using conntrack. But, I didn&amp;#039;t see the record in conntrackd cache</description>
<pubDate>30 Aug  2007 04:41:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68864</link>
</item><item>
<title>Alternatives to window shaping?</title>
<description>I have posted this before under another thread, but did not get many replies. So I thought I would post it under a more appropriate subject. OK, so</description>
<pubDate>30 Aug  2007 03:45:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68862</link>
</item><item>
<title>iptables: Unknown error 4294967295</title>
<description>Hi I am getting the error as mentioned below; the problem arose when I  have changed the data structure of the ipt_entry which stores the rules  an</description>
<pubDate>30 Aug  2007 02:42:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68859</link>
</item><item>
<title>Debugging network problems</title>
<description>Hello! My network was just changed from a vanilla ADSL connection to direct ftth. There is now a network connector with a 100MB/s entry, which gets</description>
<pubDate>29 Aug  2007 03:33:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68816</link>
</item><item>
<title>Netfilter_queue test program question</title>
<description>I&amp;#039;ve been attempting to play with netfilter_queue to see how effective a certain similarity hashing technique would work for identifying parts of docu</description>
<pubDate>29 Aug  2007 01:13:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68813</link>
</item><item>
<title>[ANNOUNCE] ipset 2.3.0 released</title>
<description>Hi, I&amp;#039;m happy to announce the new ipset release. The main changes are  - jiffies rollover bug in iptree type fixed (reported by Lukasz Nierycho</description>
<pubDate>28 Aug  2007 04:05:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68801</link>
</item><item>
<title>Re-2: Change ip_conntrack_sip default port</title>
<description>You are right, indeed I have just tested and that doesn&amp;#039;t work, it&amp;#039;s just to follow traffic bound to sip. I thus will use your solution which after te</description>
<pubDate>28 Aug  2007 01:39:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68798</link>
</item><item>
<title>Example-module for ip_queue</title>
<description>hi,  I search for an small example-module (I&amp;#039;m right that patch-o-matic is a ip_queue-Application?) which is used by ip_queue - yes the old one for 2</description>
<pubDate>27 Aug  2007 08:31:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68790</link>
</item><item>
<title>Limit match ! and and question (manpage error?)</title>
<description>According to the manpage for iptables:   limit    This module matches at a limited rate using a token bucket filter.  A rule using this exte</description>
<pubDate>27 Aug  2007 08:01:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68788</link>
</item><item>
<title>Implement single firewall login for access to all ports on LAN?</title>
<description>The normal apologies for the noobie-type question... We have IPCop nicely segregating our orange (DMZ) and green (blocked) LANs. As time has gone on,</description>
<pubDate>27 Aug  2007 07:45:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68786</link>
</item><item>
<title>PREROUTING problem</title>
<description>Hello, I have the following problem   LAN ---------------------------------Etch Linux Firewall-----------------------------------------------------</description>
<pubDate>27 Aug  2007 07:26:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68784</link>
</item><item>
<title>Sometimes SNAT is not working</title>
<description>Hello, I am using some internal IPs (169.254.x.x) on my box and then performing SNAT and DNAT from/to this IP to/from actual public IP. It has been</description>
<pubDate>27 Aug  2007 01:35:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68779</link>
</item><item>
<title>Question about /etc/iptables.down.rules</title>
<description>I have a very simple set of iptables rules: # iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT # iptables -A INPUT -p tcp -i eth0 --d</description>
<pubDate>26 Aug  2007 18:51:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68774</link>
</item><item>
<title>Accept packets when QUEUE is down</title>
<description>Hi,  I have an application that monitors packets being forwarded through the machine using a simple rule in the iptables.  Chain FORWARD (policy AC</description>
<pubDate>26 Aug  2007 14:38:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68901</link>
</item><item>
<title>Netfilter/Iptables Architecture</title>
<description>Hi Currently I am studying the architecture of netfilter/iptables and unfortunately I didnt find much information regarding them. Although different</description>
<pubDate>25 Aug  2007 16:57:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68766</link>
</item><item>
<title>Iptables List operation</title>
<description>Hi I am working on some performance measures of the IPtables these days. I want to know; Is it possible that output of iptables list command i.e. ip</description>
<pubDate>25 Aug  2007 16:27:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68765</link>
</item><item>
<title>psd macth</title>
<description>where is I&amp;#039;m to the put psd macth? Att. -- Leandro Moreira Linux Networking Telefone: +55 (32) 9197-7909 E-mail/MSN: leandro@leandromoreira.eti.b</description>
<pubDate>25 Aug  2007 12:20:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68757</link>
</item><item>
<title>netfilter optimization.</title>
<description>I&amp;#039;m looking for some firewall tweaking advice. We have a dedicated firewall which hit ran out of conntrack slots recently. We had already tweaked th</description>
<pubDate>25 Aug  2007 10:38:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68756</link>
</item><item>
<title>Interface forwarding</title>
<description>Hi, :) I&amp;#039;m working on a special sort of VPN. I&amp;#039;m suppose to do it using TUN/TAP driver. All I need is to forward (or any other appropriate technical</description>
<pubDate>25 Aug  2007 03:52:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68753</link>
</item><item>
<title>match time &amp;amp; kernel 2.6.22.5</title>
<description>Hi all, I want to add the match time. I apply the last snapshot with this patch ( patch-o-matic-ng-20060702) The compilation stop after with this er</description>
<pubDate>25 Aug  2007 02:58:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68752</link>
</item><item>
<title>question about String</title>
<description>Hello, how do i configure that all mp3 extention will block using iptables --string value? is this correct? /sbin/iptables -I INPUT -j DROP -p tcp</description>
<pubDate>24 Aug  2007 00:50:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68746</link>
</item><item>
<title>Routing to DMZ with multiple ISP&amp;#039;s</title>
<description>Ok, I&amp;#039;m hitting my head on a brick wall of my ignorance here. I have 10 DSL routers with associated internet connections. They are all configured to</description>
<pubDate>23 Aug  2007 18:37:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68743</link>
</item><item>
<title>stop/start iptables vs. &amp;quot;iptables-restore&amp;quot;</title>
<description>Hi folks, We run a linux based product (RHEL4 based, kernel-2.6.9-55, and iptables-1.2.11). During the running of the product, when we make changes</description>
<pubDate>23 Aug  2007 17:32:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68742</link>
</item><item>
<title>Change ip_conntrack_sip default port</title>
<description>Hi,  I tried to change the default port of sip_contrack and h323_conntrack in iptables. The problem is those conntrack are &amp;quot;hard compiled&amp;quot; in the ker</description>
<pubDate>23 Aug  2007 08:30:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68739</link>
</item><item>
<title>Traffic shaping questions and possible extensions</title>
<description>Hi, It has been quite a while since I looked at what was happening in Linux traffic shaping, so I am not sure if this has been discussed / improved</description>
<pubDate>23 Aug  2007 08:28:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68747</link>
</item><item>
<title>about ipt_string</title>
<description>Hi, I am just wondering why this script don&amp;#039;t block  iptables -A INPUT -p tcp -m string --string &amp;#039;bittorent&amp;#039; --algo kmp -d 0/0 --dport 80 -j REJECT</description>
<pubDate>22 Aug  2007 18:19:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68729</link>
</item><item>
<title>iptables recent, what have I done wrong?</title>
<description>I am trying to use the recent module to block all traffic from policy violators. I have got it working to ignore people who get ping happy, but I can</description>
<pubDate>22 Aug  2007 06:23:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68723</link>
</item><item>
<title>question on conntracd</title>
<description>Hi, I have a couple of question on conntrackd 1) could anyone share results of testing highly loaded system with synchronization of conntrack tables</description>
<pubDate>22 Aug  2007 05:10:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68721</link>
</item><item>
<title>where is the match PSD</title>
<description>Peoples, Sorry my bad English, is not my natural language. My doubt is following. In the older version of the patch - o - matic (20040706), the PSD</description>
<pubDate>21 Aug  2007 15:58:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68744</link>
</item><item>
<title>Rout looping through local host.</title>
<description>After many many hours of frustration and failures I&amp;#039;m almost to the point that I don&amp;#039;t think this is even currently possible with Linux. With out go</description>
<pubDate>21 Aug  2007 09:14:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68715</link>
</item><item>
<title>Firewall Issues</title>
<description>Hi all, I have an issue with my linux iptables firewall and cannot figure out what to do. I will make this as short and sweet as I can. My Network is</description>
<pubDate>21 Aug  2007 05:05:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68899</link>
</item><item>
<title>ipset performance question</title>
<description>Greetings. I&amp;#039;m working on a rules compiler that takes advantage of ipset and I&amp;#039;d like to hear opinions on the following subject: When firewall rules</description>
<pubDate>20 Aug  2007 16:30:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68702</link>
</item><item>
<title>Port forwarding inside local domain</title>
<description>Hi, just another question. Let my router be 192.168.7.33 with interfaces eth0 and ppp0; then this works perfectly here:  # iptables -t nat -A PRERO</description>
<pubDate>20 Aug  2007 07:11:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68684</link>
</item><item>
<title>REJECT target not as policy</title>
<description>Hi,  on one of my machines the REJECT target doesn&amp;#039;t behave as I expect. It is inserted into a chain but it is not accepted as a policy. myhost ~ #</description>
<pubDate>20 Aug  2007 06:52:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68682</link>
</item><item>
<title>ipt_time.c problem</title>
<description>Hello, all. I have encountered the problem of compiling &amp;quot;time&amp;quot; match extension for 2.6.21.5 kernel. After searching netfilter-devel-maillist I have f</description>
<pubDate>20 Aug  2007 05:36:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68681</link>
</item><item>
<title>interesting behavior of ftp helper</title>
<description>Hello Guys,   I have always read on documentations and messages on this mailing list that the several helpers available for netfilter would &amp;#039;recog</description>
<pubDate>19 Aug  2007 16:14:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68676</link>
</item><item>
<title>Problem using -p udp</title>
<description>Hi, I have been using Iptables on linux 2.4.26 for several years. I am running on an Axis platform (cris architecture). Recently I started moving my</description>
<pubDate>19 Aug  2007 15:37:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68675</link>
</item><item>
<title>Re: RES: RES: IPtables settings to access a backup FTP</title>
<description>thanks but I don&amp;#039;t understant about the eth1, my network only runs on eth0 ... could you explain what the whole line does? Thanks ! Patrik a écrit</description>
<pubDate>18 Aug  2007 12:58:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68669</link>
</item><item>
<title>Re: RES: IPtables settings to access a backup FTP</title>
<description>Hi thanks, could you explain what this line does ? This is what I understand : Foward incomming form eth0 to Output eth1 with tcp port 21 but I dont</description>
<pubDate>18 Aug  2007 12:26:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68668</link>
</item><item>
<title>IPtables settings to access a backup FTP</title>
<description>Hello, this is my first message so I hope I&amp;#039;m doing this right ! :) I&amp;#039;ve got iptables setup and running well on my server and up to now I&amp;#039;ve not had</description>
<pubDate>18 Aug  2007 12:08:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68667</link>
</item><item>
<title>compile-time errors</title>
<description>Hi,  I am trying to compile libnetfilters_queue.0.0.15 with libnfnetlink-0.0.16 and am getting the following compile time errors, any help would be a</description>
<pubDate>17 Aug  2007 12:39:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68665</link>
</item><item>
<title>conntrack entries - editing</title>
<description>Hello, Is there any way how to edit/delete/create entries in the conntrack table ? Thanks for replies</description>
<pubDate>17 Aug  2007 06:56:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68660</link>
</item><item>
<title>conntrack-tools 0.0.95 compilation problem</title>
<description>Hi, I&amp;#039;ve following problem when compiling conntrack-tools v0.0.95. gcc -g -O2 -o conntrack conntrack.o ../extensions/.libs/libct_proto_tcp.a ../exte</description>
<pubDate>17 Aug  2007 01:57:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68645</link>
</item><item>
<title>packet replication</title>
<description>Hi, I have a couple of questions regarding netfilter capability. I am building a network management system (a set of servers and software on a large</description>
<pubDate>16 Aug  2007 22:14:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68641</link>
</item><item>
<title>--reject-with tcp-reset doesn&amp;#039;t work in IPv6</title>
<description>I&amp;#039;m trying to figure out how to set up a rule to reply properly to a connection attempt to a filtered port, with no success. ip6tables -I INPUT -p tc</description>
<pubDate>16 Aug  2007 08:19:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68634</link>
</item><item>
<title>SNAT trouble: Linux box ignores incoming packets</title>
<description>I&amp;#039;ve got a rather bizarre configuration: Linux box has 4 ethernet devices (eth0, eth1, eth2, and eth3). eth2 and eth3 are looking to Internet, eth0 is</description>
<pubDate>16 Aug  2007 07:59:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68631</link>
</item><item>
<title>iptables v1.3.8: can&amp;#039;t initialize iptables table `filter&amp;#039;</title>
<description>Hi, I just updated to linux kernel 2.1.22 and when trying to use iptables, I get the following answer: # iptables -L iptables v1.3.8: can&amp;#039;t initiali</description>
<pubDate>15 Aug  2007 01:31:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68617</link>
</item><item>
<title>revisit: ipset nethash set type limited to /31</title>
<description>Hi, My employer has an interest in having enhancing the functionality of netfilter/trunk/ipset/ipset_nethash.c with the 2.6.18+ kernels and is explor</description>
<pubDate>14 Aug  2007 21:56:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68614</link>
</item><item>
<title>Forward port to openvpn client</title>
<description>Hi, I want to forward port 3739 on my firewall (openvpn server) to an openvpn client on port 3739. This is my setup: firewall: external interface:</description>
<pubDate>14 Aug  2007 14:59:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68611</link>
</item><item>
<title>change from eth0 ---- router interface , to ppp0 --- ethernet modem interface</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I finally changed device to connect to internet on my gateway linux box , from a netgear router to an e</description>
<pubDate>14 Aug  2007 13:32:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68610</link>
</item><item>
<title>Capitalization conflicts in netfilter code apparently break tortise subversion</title>
<description>I am sorry if this is a frequently raised topic, but I have done some web searches for it, including ones limited to netfilter.org, and looked through</description>
<pubDate>14 Aug  2007 10:33:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68606</link>
</item><item>
<title>libipq</title>
<description>I&amp;#039;m trying to use the libipq fucntions such as ipq_create_handle in C, but I keep getting the error  too many arguments to function `ipq_create_handl</description>
<pubDate>14 Aug  2007 10:33:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68605</link>
</item><item>
<title>about the nfq_set_queue_maxlen function</title>
<description>Dear Scott,    You can download the newest &amp;quot;libnfnetlink&amp;quot; library from the www.netfilter.org. And when you successfully install the new library, yo</description>
<pubDate>14 Aug  2007 07:21:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68595</link>
</item><item>
<title>error - but I don&amp;#039;t know where....</title>
<description>Hi * I just try setup firewall. Config is following: Desktop        Firewll  (192.168.1.1) ------Eth0  Eth1(91.189.74.10)---------ISP Scri</description>
<pubDate>14 Aug  2007 02:59:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68589</link>
</item><item>
<title>not [!] rule is not working</title>
<description>Hi, I was trying to drop arp packets such that only specific interface should answer the arp requests. I added following rules in input chain. -j DROP</description>
<pubDate>13 Aug  2007 23:45:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68586</link>
</item><item>
<title>rule limit question</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 For relatively obscure reasons, I am trying to build a set of rules that run into the hundreds of thous</description>
<pubDate>13 Aug  2007 15:52:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68577</link>
</item><item>
<title>iptables /nat and route</title>
<description>Hi, it seems it is a simple task, but can&amp;#039;t get it going. I want have a couple of private machines accessing a public one (and other way around) thro</description>
<pubDate>13 Aug  2007 01:58:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68571</link>
</item><item>
<title>How to NAT Cisco&amp;#039;s &amp;quot;Skinny&amp;quot; (SCCP) protocol?</title>
<description>Hi all! Seems like I&amp;#039;m getting out on the deep water here, but how do I NAT Cisco&amp;#039;s SCCP protocol? I&amp;#039;m trying to do this on a Linksys (WRT54G) route</description>
<pubDate>13 Aug  2007 01:51:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68570</link>
</item><item>
<title>trying to block an internal ip</title>
<description>-- I have been trying to block all traffic from an internal ip address, and packets are still going out, (seen with tcpdump) I don&amp;#039;t see any traffic</description>
<pubDate>12 Aug  2007 20:15:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68568</link>
</item><item>
<title>Re: iptables/mac address filtering question (nfcan: to exclusive)</title>
<description>On 08/11/2007 01:46:51 PM, Jay Sprenkle - jsprenkle@gmail.com wrote: .... &amp;gt; I&amp;#039;ve put in a rule in my iptables chain but notice when I try to &amp;gt; connec</description>
<pubDate>11 Aug  2007 11:55:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68560</link>
</item><item>
<title>iptables/mac address filtering question</title>
<description>Good morning all, I&amp;#039;m already aware mac address is easily spoofed but I&amp;#039;d like to make it just a little bit harder to break into my system anyway. I&amp;#039;</description>
<pubDate>11 Aug  2007 10:46:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68558</link>
</item><item>
<title>pptp</title>
<description>Dear all, i am using linux as firewall and proxy server, having some problem regarding Microsoft VPN, my network users connect Microsoft vpn server.</description>
<pubDate>11 Aug  2007 00:59:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68552</link>
</item><item>
<title>queue_max_length configuration</title>
<description>I need to increase the default size of the queue_max_length but do not see where in the code this is defined. Can someone send me a pointer to the loc</description>
<pubDate>10 Aug  2007 11:24:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68550</link>
</item><item>
<title>NAT performance + table processing</title>
<description>Hi, I wrote some performance tests of NAT table. The main idea is, that I add 10000 random+senseless rules to the NAT table (snat, postrouting) and t</description>
<pubDate>09 Aug  2007 10:44:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68548</link>
</item><item>
<title>NAT preformance and table processing</title>
<description>Hi, I wrote some performance tests of NAT table. The main idea is, that I add 10000 random+senseless rules to the NAT table (snat, postrouting) and t</description>
<pubDate>09 Aug  2007 10:33:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68547</link>
</item><item>
<title>ACCOUNT is accounting only 1 direction</title>
<description>Hello, I tried to use ACCOUNT to see passing data and make graphs from it, but I see only one direction. # iptables -A FORWARD -j ACCOUNT --addr 0.0</description>
<pubDate>09 Aug  2007 06:04:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68545</link>
</item><item>
<title>pptp-conntrack question</title>
<description>Hello, all. I have spent nearly a week trying to solve my problem and is almost entirely stuck. I would appreciate any help or advise. In addition to</description>
<pubDate>09 Aug  2007 00:17:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/user/68544</link>
</item>
</channel>
</rss>
