From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1030290AbWDOQzw (ORCPT ); Sat, 15 Apr 2006 12:55:52 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1030291AbWDOQzv (ORCPT ); Sat, 15 Apr 2006 12:55:51 -0400 Received: from mx7.mail.ru ([194.67.23.27]:20560 "EHLO mx7.mail.ru") by vger.kernel.org with ESMTP id S1030290AbWDOQzv (ORCPT ); Sat, 15 Apr 2006 12:55:51 -0400 From: Andrey Borzenkov To: Patrick McHardy Subject: Re: Openswan, iptables (fiaif) and 2.6.16 kernel Date: Sat, 15 Apr 2006 20:55:47 +0400 User-Agent: KMail/1.9.1 Cc: linux-kernel@vger.kernel.org Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200604152055.48130.arvidjaar@mail.ru> Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > 2.6.16 does a second policy lookup after SNAT, you probably SNAT > the packets to an address that doesn't match the policy anymore. Could you please give pointers where is it documented? All documents I have suggest that SNAT is done as the last step, so any rule should use real and not SNAT'ed address. Thank you Andrey -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFEQSWUR6LMutpd94wRAtJ0AJ45p5p54hDdyyjBPWejRtlr+DoNdQCgy1/3 H2MtVmha+rE6vRxzkdSrrI8= =RHjq -----END PGP SIGNATURE-----