[Bug 429] -j REDIRECT does not appear to work correctly

bugzilla-daemon at bugzilla.netfilter.org bugzilla-daemon at bugzilla.netfilter.org
Wed Feb 22 06:31:42 CET 2006


https://bugzilla.netfilter.org/bugzilla/show_bug.cgi?id=429





------- Additional Comments From James.Schatzman at futurelabusa.com  2006-02-22 06:31 MET -------
Per the request, here is the TCPDUMP output for REDIRECT (which fails) and DNAT
(which succeeds) when I attempt to make a connection from an external host:

Using REDIRECT  (Connection refused):

21:11:56.367886 IP 67.172.153.238.49840 > 216.152.242.200.80: S
3934967357:3934967357(0) win 65535 <mss 1460,nop,wscale 3,nop,nop,sackOK>
21:11:56.367918 IP 216.152.242.200.80 > 67.172.153.238.49840: R 0:0(0) ack
3934967358 win 0
21:11:56.807008 IP 67.172.153.238.49840 > 216.152.242.200.80: S
3934967357:3934967357(0) win 65535 <mss 1460,nop,wscale 3,nop,nop,sackOK>
21:11:56.807030 IP 216.152.242.200.80 > 67.172.153.238.49840: R 0:0(0) ack 1 win 0
21:11:56.367886 IP 67.172.153.238.49840 > 216.152.242.200.80: S
3934967357:3934967357(0) win 65535 <mss 1460,nop,wscale 3,nop,nop,sackOK>
21:11:56.367918 IP 216.152.242.200.80 > 67.172.153.238.49840: R 0:0(0) ack
3934967358 win 0
21:11:56.807008 IP 67.172.153.238.49840 > 216.152.242.200.80: S
3934967357:3934967357(0) win 65535 <mss 1460,nop,wscale 3,nop,nop,sackOK>
21:11:56.807030 IP 216.152.242.200.80 > 67.172.153.238.49840: R 0:0(0) ack 1 win 0


Using DNAT (Connection accepted):

21:15:47.344162 IP 67.172.153.238.49911 > 216.152.242.200.80: S
4118844061:4118844061(0) win 65535 <mss 1460,nop,wscale 3,nop,nop,sackOK>
21:15:47.344209 IP 216.152.242.200.80 > 67.172.153.238.49911: S
1542935862:1542935862(0) ack 4118844062 win 5840 <mss
1460,nop,nop,sackOK,nop,wscale 2>
21:15:47.398702 IP 67.172.153.238.49911 > 216.152.242.200.80: . ack 1 win 64240



-- 
Configure bugmail: https://bugzilla.netfilter.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You reported the bug, or are watching the reporter.



More information about the netfilter-buglog mailing list