2.6.16-rc1-mm3 XFRM+NAT issue

Patrick McHardy kaber at trash.net
Mon Jan 30 00:26:41 CET 2006


Christophe Saout wrote:
> Am Sonntag, den 29.01.2006, 23:59 +0100 schrieb Patrick McHardy:
> 
> 
>>Found it, the packet doesn't have its dst_entry released after DNAT in
>>PRE_ROUTING because of an incorrect check and is delivered locally.
>>This patch should fix it.
> 
> 
> Ha! You got it. Nice.
> 
> Looks like I can finally move on trying to upgrade my kernel...

Actually it seems I got confused, the check looks right. Can you post
the output of /proc/net/ip_conntrack for this connection please?



More information about the netfilter-devel mailing list