Thu, 5 Jul 2001 02:22:19 -0300
On Fri, Jun 29, 2001 at 08:40:21PM -0700, Jeremy Mann wrote:
> Ok, I have traced all problems to something on the
> Input chain. I have enabled IP_CONNTRACK_IRC and
yup. You are talking about 'back through the firewall' but
use the INPUT chain.
Either you are only talking about a 'normal host' (one network
interface, no routing) and you filter in the INPUT chain, OR
you have a firewall (router, multiple interfaces) and use
the FORWARD chain with regard to your stateful firewalling
for hosts behind the firewall.
the semantics of INPUT / FORWARD / OUTPUT has changed from ipchains to
Live long and prosper
- Harald Welte / email@example.com http://www.gnumonks.org/
GCS/E/IT d- s-: a-- C+++ UL++++$ P+++ L++++$ E--- W- N++ o? K- w--- O- M-
V-- PS+ PE-- Y+ PGP++ t++ 5-- !X !R tv-- b+++ DI? !D G+ e* h+ r% y+(*)