On 3/17/13 2:15 PM, "TJ" <[email protected]> wrote:

>On 17/03/13 18:33, Tom Eastep wrote:
>>> /etc/shorewall/masq
>>> #INTERFACE          SOURCE          ADDRESS         PROTO   PORT(S) IPSEC   
>>> MARK
>>> ppp0        10.0.0.0/8,169.254.0.0/16,172.16.0.0/12,192.168.0.0/16  
>>> 82.71.24.87
>>> 
>>>#ppp1        10.0.0.0/8,169.254.0.0/16,172.16.0.0/12,192.168.0.0/16  
>>>82.71.24.87
>>> eth9        br0
>>> tun0    10.0.0.0/8,127.0.0.0/8 10.254.252.18
>>> #tun0    br0
>>>
>> 
>> That masq entry certainly won't change the SOURCE ip from 82.71.24.87 to
>> 10.254.252.18. It only works for 10.0.0.0/8 in the SOURCE (you can't NAT
>> 127.0.0.0/8 so that part of the rule is just extra noise).
>
>Of course! I think I added 127.0.0.0/8 in desperation when testing
>connections from local processes on Jeeves.
>
>The problem seems to be something to do with packet marking - I tried it
>manually for a client on the LAN and it works fine:
>
>$ ip route add default via 10.254.252.17 dev tun0 table VPN
>$ ip rule add from 10.254.251.50 lookup VPN prio 10001
>$ echo 0 > /proc/sys/net/ipv4/conf/tun0/rp_filter
>
>But if I try marking HTTP packers it fails when using:
>
>$ ip rule del from 10.254.251.50 lookup VPN prio 10001
>$ ip rule add fwmark 0x50/0xffffffff lookup VPN
>$ iptables -t mangle -A tcfor -p tcp --dport 80 -j MARK --set-xmark
>0x50/0xffffffff
>
>Which - apart from using table 'tcfor' instead of 'tcout' - is the same
>as the Shorewall rule. The Shorewall rule remains, too:
>
>$ sudo iptables -t mangle -S
>[sudo] password for tj:
>-P PREROUTING ACCEPT
>-P INPUT ACCEPT
>-P FORWARD ACCEPT
>-P OUTPUT ACCEPT
>-P POSTROUTING ACCEPT
>-N tcfor
>-N tcin
>-N tcout
>-N tcpost
>-N tcpre
>-A PREROUTING -j tcpre
>-A INPUT -j tcin
>-A FORWARD -j MARK --set-xmark 0x0/0xff
>-A FORWARD -j tcfor
>-A OUTPUT -j tcout
>-A POSTROUTING -j tcpost
>-A tcfor -p tcp -m tcp --dport 80 -j MARK --set-xmark 0x50/0xffffffff
>-A tcout -p tcp -m tcp --dport 80 -j MARK --set-xmark 0x50/0xffffffff

You must do your marking in the PREROUTING chain.

-Tom
You do not need a parachute to skydive. You only need a parachute to
skydive twice.





------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to