Re: stateless 1:1 NAT

2007-11-09 Thread Florin Andrei
Herbert Xu wrote: Florin Andrei <[EMAIL PROTECTED]> wrote: OK, if I download 2.6.24-rc1, will it have this feature already? Yes. OK, I want to test this feature with 2.6.24-rc2. I compiled iproute2-2.6.23 with your patch applied. The problem is, I have no experience with tc (and very little

Re: stateless 1:1 NAT

2007-10-26 Thread Florin Andrei
download does not even complete, and of course a new one doesn't start. I may test 2.6.24 and stateless 1:1 NAT and we'll see what happens. I've been told that stateless 1:1 NAT is already in the .24_rc1 so I may test that. -- Florin Andrei http://florin.myip.org/ - To unsubs

Re: stateless 1:1 NAT

2007-10-24 Thread Herbert Xu
Florin Andrei <[EMAIL PROTECTED]> wrote: > > OK, if I download 2.6.24-rc1, will it have this feature already? Yes. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.o

Re: stateless 1:1 NAT

2007-10-24 Thread Florin Andrei
Herbert Xu wrote: Florin Andrei <[EMAIL PROTECTED]> wrote: I've heard that stateless 1:1 NAT will be possible with the upcoming 2.6.24 kernel. I'd like to test that feature, but I'm not sure when it will actually be included. Will it be present in the release candidate

Re: stateless 1:1 NAT

2007-10-17 Thread Herbert Xu
Florin Andrei <[EMAIL PROTECTED]> wrote: > > Is it going to be possible to combine stateless 1:1 NAT with stateful > filtering? It is but it's pointless unless you can somehow enumerate the bad guys (or a superset of them) and redirect them to NOTRACK. Cheers, -- Vi

Re: stateless 1:1 NAT

2007-10-17 Thread Florin Andrei
Patrick McHardy wrote: And Linux 2.6.23? :) Alright, I get it. :-) Building kernel 2.6.23.1 as we speak. -- Florin Andrei http://florin.myip.org/ - To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://v

Re: stateless 1:1 NAT

2007-10-17 Thread Patrick McHardy
hat should make it behave much better in the scenario you describe. It would be interesting if you could test that. Alternatively you could of course just increase the maximum number of conntracks. Is it going to be possible to combine stateless 1:1 NAT with stateful filtering? Yes, but that

Re: stateless 1:1 NAT

2007-10-17 Thread Florin Andrei
Herbert Xu wrote: Florin Andrei <[EMAIL PROTECTED]> wrote: I've heard that stateless 1:1 NAT will be possible with the upcoming 2.6.24 kernel. I'd like to test that feature, but I'm not sure when it will actually be included. Will it be present in the release candidate

Re: stateless 1:1 NAT

2007-10-16 Thread Herbert Xu
Florin Andrei <[EMAIL PROTECTED]> wrote: > I've heard that stateless 1:1 NAT will be possible with the upcoming > 2.6.24 kernel. > I'd like to test that feature, but I'm not sure when it will actually be > included. Will it be present in the release candi

stateless 1:1 NAT

2007-10-16 Thread Florin Andrei
I've heard that stateless 1:1 NAT will be possible with the upcoming 2.6.24 kernel. I'd like to test that feature, but I'm not sure when it will actually be included. Will it be present in the release candidates for 2.6.24? I just need a somewhat stable kernel tree to play w