[Bug 1227] Current conntrack state isn't considered when evaluating multiple SNAT rules

bugzilla-daemon at netfilter.org bugzilla-daemon at netfilter.org
Sun Feb 18 13:44:42 CET 2018


--- Comment #1 from richard at helix.net.nz ---
Apparently this functionality was removed in 2.6.11-rc1:

"In  Kernels up to 2.6.10, you can add several --to-source options.
For those kernels, if  you  specify more  than  one  source  address,
either via an address range or multiple --to-source options, a simple
round-robin  (one  after another  in  cycle)  takes place between
these addresses.  Later Kernels (>=  2.6.11-rc1)  don't  have  the
ability  to  NAT  to multiple ranges anymore."

