[RFC] MASQUERADE / policy routing ("Route send us somewhere else")

Julian Anastasov ja at ssi.bg
Wed Sep 1 07:04:29 CEST 2004


On Wed, 1 Sep 2004, Herbert Xu wrote:

> > I was mistaken.  In the mpath case there is no source address per
> > nexthop.
> Actually, that should still work.
> For example, if you're like me and the nexthops all go to different
> devices then it's obviously OK as inet_select_addr will pick the
> right one for the device.  If they're going through the same device
> but to different gateways then it'll still pick the right one for
> the given gateway.

	Yes, if the targets are from some of the GW's subnets. It
is a masquerade drawback not to match by GW because the routing
does not support it but the world is not perfect.


Julian Anastasov <ja at ssi.bg>

More information about the netfilter-devel mailing list