mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* solved it (at lest for me) "MASQUERADE: Route sent us somewhere else."
@ 2004-01-09  3:52 Neal Stephenson
  2004-01-09  9:46 ` Anders Westrup
  0 siblings, 1 reply; 2+ messages in thread
From: Neal Stephenson @ 2004-01-09  3:52 UTC (permalink / raw)
  To: linux-kernel

Hi,

	I figured out my routing problems which were causing

MASQUERADE: Route sent us somewhere else.

messages from the kernel. I use iptables to masquerade and mangle
packets so with the advanced router features i can send it out
appropriate interfaces (i.e. web traffic out my residential ISP service
not my commercial ISP service). See the earlier thread on this for more
info (Subject 2.4.23 masquerading broken?). I got a useful reply from
Martin Josefsson who suggested that ipt_MASQUERADE could no longer find
the input-interface anymore. Upon further investigation and it seems all
the rules with iif or from in them no longer work (at least for me). So
rules like the following will cause the error in post 2.4.22 kernels.

ip rule add pri 420 from IP lookup TABLE

I now use exclusively rules of the form 

ip rule add pri 420 fwmark MARK table TABLE

and mark all packets needing special routing with mangling rules such as

iptables -t mangle -A PREROUTING -s IP -j MARK --set-mark MARK

this seems to prevent the problem. Don't know what changed in the
kernel.

		Neal


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: solved it (at lest for me) "MASQUERADE: Route sent us somewhere else."
  2004-01-09  3:52 solved it (at lest for me) "MASQUERADE: Route sent us somewhere else." Neal Stephenson
@ 2004-01-09  9:46 ` Anders Westrup
  0 siblings, 0 replies; 2+ messages in thread
From: Anders Westrup @ 2004-01-09  9:46 UTC (permalink / raw)
  To: Neal Stephenson; +Cc: linux-kernel

Hi,

I have another solution to the same problem. I also use multiple external
interfaces and select outgoing interface via:

ip rule add from IP/range lookup TABLE

With 2.4.23 iptables -j MASQUERADE stopped working, reporting:
MASQUERADE: Route sent us somewhere else.

In my case the solution was to change my masquerade rule

iptables -t nat -A POSTROUTING -o IF -s IP/range -j MASQUERADE

to SNAT instead:

iptables -t nat -A POSTROUTING -o IF -s IP/range -j SNAT --to-source EXT-IP

With this config everything works as before 2.4.23.

regards
Anders Westrup

On Thu, Jan 08, 2004 at 10:52:26PM -0500, Neal Stephenson wrote:
> Hi,
> 
> 	I figured out my routing problems which were causing
> 
> MASQUERADE: Route sent us somewhere else.
> 
> messages from the kernel. I use iptables to masquerade and mangle
> packets so with the advanced router features i can send it out
> appropriate interfaces (i.e. web traffic out my residential ISP service
> not my commercial ISP service). See the earlier thread on this for more
> info (Subject 2.4.23 masquerading broken?). I got a useful reply from
> Martin Josefsson who suggested that ipt_MASQUERADE could no longer find
> the input-interface anymore. Upon further investigation and it seems all
> the rules with iif or from in them no longer work (at least for me). So
> rules like the following will cause the error in post 2.4.22 kernels.
> 
> ip rule add pri 420 from IP lookup TABLE
> 
> I now use exclusively rules of the form 
> 
> ip rule add pri 420 fwmark MARK table TABLE
> 
> and mark all packets needing special routing with mangling rules such as
> 
> iptables -t mangle -A PREROUTING -s IP -j MARK --set-mark MARK
> 
> this seems to prevent the problem. Don't know what changed in the
> kernel.
> 
> 		Neal
> 
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/

-- 
--------------------------------------------
Anders Westrup <anders@barbanet.com>
echo '[lddx%Px/dsnK<b]dsb203953535806376680189225555sn[ln128]sdx' | dc

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2004-01-09  9:46 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-01-09  3:52 solved it (at lest for me) "MASQUERADE: Route sent us somewhere else." Neal Stephenson
2004-01-09  9:46 ` Anders Westrup

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®