iptables OUTPUT SNAT

Ladislav Kaderják laco na unicom.sk
Pondělí Leden 28 12:09:16 CET 2002


je mozne robit SNAT pre OUTPUT chain ?

mam totiz problem s ktorym si neviem rady

root# iptables -A OUTPUT -t nat -d 192.168.1.1  -j SNAT --to-source=192.168.1.11
iptables: Invalid argument
          ^^^^^^^^^^^^^^^^ postrouting ide output nie

root# iptables -t nat -L                                                             Chain PREROUTING (policy ACCEPT)
target     prot opt source               destination         

Chain POSTROUTING (policy ACCEPT)
target     prot opt source               destination         
MASQUERADE  all  --  anywhere             anywhere           
SNAT       all  --  anywhere             192.168.1.1  to:192.168.1.11

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination       



eth2      Link encap:Ethernet  HWaddr 00:00:B4:91:D9:A4  
          inet addr:192.168.1.10 Bcast:195.72.6.127  Mask:255.255.255.128
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:8643 errors:0 dropped:0 overruns:0 frame:0
          TX packets:7496 errors:0 dropped:0 overruns:0 carrier:0
          collisions:3 txqueuelen:100 
          RX bytes:3539970 (3.3 Mb)  TX bytes:1850665 (1.7 Mb)
          Interrupt:10 Base address:0xce00 

eth2:0    Link encap:Ethernet  HWaddr 00:00:B4:91:D9:A4  
          inet addr:192.168.1.11 Bcast:195.72.6.127  Mask:255.255.255.128
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          Interrupt:10 Base address:0xce00 


-- 
laco na unicom.sk Ladislav Kaderjak
www.unicom.sk  UNICOM Computer & Telematic, s.r.o.



Další informace o konferenci Linux