why isn't masquerade working?

Edmundo Carmona eantoranz at gmail.com
Fri Jul 22 04:06:45 CEST 2005


This is the first time I ever see this kind of problem... maybe it's
because I have such a weird configuration right now.

I'm testing a host with two internet connections.

the default route is only one of the two connections. The other link
is not involved at all. However, I set a rule in OUTPUT mangle that
will mark icmp traffic and then I have an ip rule that forces it to
use a routing table that is configured to use the "unused link".

I thought that it meant that icmp would come out from that interface..
and as I am masquerading traffic through that interface, the src
address would be set to that interface's address.

It's a BIG surprise to see that it's not happening.  I tcpdumped
traffic and noticed that traffic is coming through the unused
interface... but still has the src address of the other interface. Is
that normal?

And how can I make it to use the "correct" address?



More information about the netfilter mailing list