由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
THU版 - Re: how to do this iptables setup? (转载)
相关主题
Virginia Tech Real-Time实验室招人信息802.11的MAC是否对packet loss之后都会double backoff window?
在 Los Angeles 做 real estate 的清华校友?问个firewall(iptables)的问题
急:如何提高external monitor (of a laptop)的resolution?一个load balancer的问题
how to do this iptables setup?紧急求助!
trick to use JMX on EC2port forwarding 求助
trick to use JMX on EC2 (转载)远程ssh router的问题
iptables高手看过来,哪些端口是必需的?谁知道tomato的设置文件存在哪里?
怎样把snoop的结果抽出来(假设已变成hexadecimal and ASCII format)?how to do this Iptables setting?
相关话题的讨论汇总
话题: ip话题: box话题: client话题: iptables话题: real
进入THU版参与讨论
1 (共1页)
c******n
发帖数: 4965
1
【 以下文字转载自 Linux 讨论区 】
发信人: creation (努力自由泳50m/45sec !), 信区: Linux
标 题: Re: how to do this iptables setup?
发信站: BBS 未名空间站 (Fri Sep 16 20:55:09 2011, 美东)
but here's what I dont' understand:
I checked the packets in wireshark.
the first packet sent out by client is REAL_IP_OF_CLIENT_BOX to 127.0.0.1
I thought according to the tutorial http://www.frozentux.net/iptables-tutorial/images/tables_traverse.jpg
after DNAT changes the dest IP, it goes through another routing decision, so
at this step it should be set to the lo interface, so MASQUERADE should set
its source to be 127.0.0.1 ???
also wireshark shows that the return ip is $EXTERNAL_BOX_IP to REAL_IP_OF_
CLIENT_BOX, this is fine. but how is my application able to receive this
packet in its TCP connection? my sshd is listening on localhost only, but
the packet is addressed to REAL_IP_OF_CLIENT_BOX
my ssh client opens a TCP connection to $EXTERNAL_BOX_IP, so the tcp
connection expects to
-j
c******n
发帖数: 4965
2
anybody familiar with network layer could help me out?
Thanks

so
set

【在 c******n 的大作中提到】
: 【 以下文字转载自 Linux 讨论区 】
: 发信人: creation (努力自由泳50m/45sec !), 信区: Linux
: 标 题: Re: how to do this iptables setup?
: 发信站: BBS 未名空间站 (Fri Sep 16 20:55:09 2011, 美东)
: but here's what I dont' understand:
: I checked the packets in wireshark.
: the first packet sent out by client is REAL_IP_OF_CLIENT_BOX to 127.0.0.1
: I thought according to the tutorial http://www.frozentux.net/iptables-tutorial/images/tables_traverse.jpg
: after DNAT changes the dest IP, it goes through another routing decision, so
: at this step it should be set to the lo interface, so MASQUERADE should set

n****I
发帖数: 731
3
NOt ask me!

so
set

【在 c******n 的大作中提到】
: anybody familiar with network layer could help me out?
: Thanks
:
: so
: set

1 (共1页)
进入THU版参与讨论
相关主题
how to do this Iptables setting?trick to use JMX on EC2
help: iptables 问题trick to use JMX on EC2 (转载)
Ubuntu的firewall?iptables高手看过来,哪些端口是必需的?
what happens to a TCP connection if one packet keeps dropping?怎样把snoop的结果抽出来(假设已变成hexadecimal and ASCII format)?
Virginia Tech Real-Time实验室招人信息802.11的MAC是否对packet loss之后都会double backoff window?
在 Los Angeles 做 real estate 的清华校友?问个firewall(iptables)的问题
急:如何提高external monitor (of a laptop)的resolution?一个load balancer的问题
how to do this iptables setup?紧急求助!
相关话题的讨论汇总
话题: ip话题: box话题: client话题: iptables话题: real