Denis denismpa at gmail.com
Tue Nov 28 18:20:10 CET 2006

Good afternoon everybody.

I'm having a problem with a SNAT and wanna know if somebody here can help-me.

the issue is as following:

I have a Proxy Load Balanced and when my users try to access bank's
sites on ssl protocol (port 443)

when the connection  is balanced by the two proxy nodes the bank site
notes that ip source change and the user is disconnected

to solve this problem I thinked to do a SNAT on my two nodes as follow

Node 1 (Ip

iptables -t nat -A POSTROUTING -p tcp -o eth1 --dport 443 -j SNAT

and on Node 2 (IP

iptables -t nat -A POSTROUTING -p tcp -o eth1 --dport 443 -j SNAT

so, the connection arrives on the destination translated as have to
be, but the connection doesn't get established.

This is as the destination machine can't return the package.

Some body have any idea to help me?

More information about the netfilter mailing list