LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel
User Name
Password
Linux - Kernel This forum is for all discussion relating to the Linux kernel.

Notices


Reply
  Search this Thread
Old 09-14-2016, 09:02 AM   #1
EgAyman
LQ Newbie
 
Registered: Sep 2016
Posts: 2

Rep: Reputation: Disabled
Thumbs up Source ip is not changed to Masqurade ip in the reply or ack packets while other packets are masquraded


Hi every one
Its my first time to share my problems here ,
I have estiblished an internet connection in my lab using two static public adresses
. I have used iptables to establish connections between the tow wans and their internal lans. I have faced some problems. I will start with this one.
I use wireshark to observe packets exiting and entering and i have noticed that :
In the case of using packets of type ICMP or TCP the reply packets and acknowledge packets does not change their source ip to the masqurade ip address of the ubuntu router.
While other packets (UDP or non reply) are masqueraded right.

Any thouths ??
Thanks
Ayman
 
Old 09-16-2016, 02:02 PM   #2
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
Are your two (2) static IP's on the same physical interface or on different physical interface?
 
Old 09-20-2016, 11:06 AM   #3
EgAyman
LQ Newbie
 
Registered: Sep 2016
Posts: 2

Original Poster
Rep: Reputation: Disabled
mangle table

Quote:
Originally Posted by lazydog View Post
Are your two (2) static IP's on the same physical interface or on different physical interface?
of course they are two different WANS as i mentioned before no common nic cards.
any way as I read about mangle table that it affects the MASQUERADE or SNAT; but as im facing rigth now that when i access the packets from inside the nfqueue program the out going packets are changed as i want, but for example if i am pinging from on wan to another the request packet goes right, but if its a reply packet MASQUERADE does not work, same as for TCP packets and its ACK packets.
 
Old 09-20-2016, 03:00 PM   #4
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
Quote:
Originally Posted by EgAyman View Post
of course they are two different WANS as i mentioned before no common nic cards.
Sorry, I did not see anything in your original post stating you were using 2 nic cards only that you are using two public IP Addresses.

Quote:
any way as I read about mangle table that it affects the MASQUERADE or SNAT; but as im facing rigth now that when i access the packets from inside the nfqueue program the out going packets are changed as i want, but for example if i am pinging from on wan to another the request packet goes right, but if its a reply packet MASQUERADE does not work, same as for TCP packets and its ACK packets.
Sorry I'm not familiar with nfqueue myself. But I am going to question where you are pulling your traffic off the wire to see that they are not being masqueraded. Do you have another device sitting between your lab and the wan that is showing you that your packets are not masqueraded? Or are you pulling them directly off the lab device?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Simple IPtables :: allow ACK packets DaveQB Linux - Networking 4 08-27-2013 08:21 PM
Outgoing torrent ACK-Packets flooding my Intranet IceDragon Linux - Networking 13 01-28-2011 07:04 AM
tc filter can't match ACK packets ivanatora Linux - Networking 4 02-10-2009 03:44 PM
Disntiguishing between ACK packets in a TCP connection!! vishamr2000 Linux - Networking 3 05-23-2006 01:08 AM
Forwarding ACK Packets snufferz Linux - Newbie 0 05-12-2004 02:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel

All times are GMT -5. The time now is 01:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration