LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-26-2018, 06:34 AM   #1
firask317
LQ Newbie
 
Registered: Feb 2012
Posts: 13

Rep: Reputation: Disabled
Some Online Services Are Not Compatible with iptables NAT


Hello there,

I work for an ISP and our CGN (Carrier Grade NAT) device suddenly stopped working. As a temporary solution, I used a high-spec Linux box with IP forwarding enabled and iptables to do the CGN. I knew that iptables is not a good option for CGN (at least when it and the kernel are not tuned properly) and I knew that some online services and applications would break (if no workarounds are in place for them), but for my surprise I was quite impressed with the performance. Everything looks fine and around 4 Gbps of traffic is being NATed properly.

However, we got a lot of complaints that Playstation and Xbox online gaming does not work. I tried to find something online but what I was able to understand is online gaming requires open NAT and it does not work with other types of NAT (Classified by Microsoft), which are moderate and strict.

Now, does anyone of you guys please have any idea about how to make the NAT done by iptables an open NAT? I believe there should be some open TCP ports, this is what I understood on the non-technical web pages talking about online gaming but I don't know how that should be done as I believe there should be an active NAT translation for a port on the client side to be accessible.

I appreciate your help!

Thanks!
Firas
 
Old 01-27-2018, 07:48 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,317
Blog Entries: 28

Rep: Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140Reputation: 6140
A web search for iptables open NAT turns up a number of articles, but I am not competent to select ones to recommend to you.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Knock: A Linux kernel patch for NAT-compatible, stealthy port knocking LXer Syndicated Linux News 0 12-12-2013 07:20 AM
iptables: can't initialize iptables table `NAT' linuxgentoo Linux - Kernel 3 01-17-2010 10:15 AM
I configure NAT and use "services ..." to save it but when I reboot there is no nat bruack Linux - Software 4 09-01-2004 02:38 AM
IPTABLES : build NAT using IPTABLES joseph Linux - Networking 4 04-23-2004 05:08 AM
using NAT to get a second computer online blahJake Linux - Networking 2 02-04-2004 10:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:17 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration