[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: ipip (gif) tunnels and npf
> 01:20:16.772680 IP 10.0.100.97 > 126.96.36.199: IP 188.8.131.52 > 184.108.40.206: ICMP echo request, id 3384, seq 0, length 64 (ipip-proto-4)
> 01:20:17.777222 IP 10.0.100.97 > 220.127.116.11: IP 18.104.22.168 > 22.214.171.124: ICMP echo request, id 3384, seq 1, length 64 (ipip-proto-4)
> They're clearly not rewritten.
NAT should look at packets on the outgoing interface and these should be
rewritten, wether they are e.g. IP+TCP or IP+IP packets shouldn't
SHOULD, yes. Although I didn't put my config in the original message, it's
exactly what you put and what's in the example configuration. From npfctl
map re0 dynamic any -> 126.96.36.199 pass family inet4 from 10.0.100.0/24
Should I create a PR?
Main Index |
Thread Index |