Michael Muenz linux at
Wed Apr 13 16:26:10 CEST 2005


> "Eduardo Spremolla" <edspremolla at> schrieb im 
> Newsbeitragnews:1113393681.4244.3.camel at
> Yes, the OpenSwan is mutch more clear, yuo have the packet with the
> originals ip in the nat post chain to the tunn0 device. 

> Is there any chance to aplay NETMAP to the source 
> ip on PREROUTING ?

I never used NETMAP but this is from the description:
It can be applied to the PREROUTING chain to alter the destination of
incoming connections, to the POSTROUTING chain to alter the source 
of outgoing connections, or both (with separate rules).

You want to alter the source ( and that's an outgoing conn.
(Of course vice versa) ..

So perhaps this will work:
iptables -t nat -A POSTROUTING -s -d \
   -j NETMAP --to
iptables -t nat -A PREROUTING -s -d \
   -j NETMAP --to

- Michael

More information about the netfilter mailing list