Networking Forums

Networking Forums > Computer Networking > Linux Networking > Iptables checksum question

Reply
Thread Tools Display Modes

Iptables checksum question

 
 
Sam
Guest
Posts: n/a

 
      07-27-2004, 01:30 AM
Hi,

Iptables question: we've managed to get ip tables working on the
ingress router to the extent that it modifies QOS bits on the IP
header as desired if the destination port is a match to the iptables
command. We'd like to have this work both ways - i.e. put communiction
over a particular port in a special diffserv class. However, when we
add the same iptables command to the egress router, the checksum is
incorrect when it arrives at the end host (Ethereal tell us this).

Question: what are we doing wrong? Is this a bug in iptables, or more
likely a lack of understanding on our part? Any answers/help much
appreciated.

Best Regards,
Sam90
 
Reply With Quote
 
 
 
 
Sam
Guest
Posts: n/a

 
      07-27-2004, 10:29 PM
(E-Mail Removed) (Sam) wrote in message news:<(E-Mail Removed). com>...
> Hi,
>
> Iptables question: we've managed to get ip tables working on the
> ingress router to the extent that it modifies QOS bits on the IP
> header as desired if the destination port is a match to the iptables
> command. We'd like to have this work both ways - i.e. put communiction
> over a particular port in a special diffserv class. However, when we
> add the same iptables command to the egress router, the checksum is
> incorrect when it arrives at the end host (Ethereal tell us this).
>
> Question: what are we doing wrong? Is this a bug in iptables, or more
> likely a lack of understanding on our part? Any answers/help much
> appreciated.
>
> Best Regards,
> Sam90


I still don't have an answer - however, I think I can avoid the
packets from getting processed twice by iptables (on in each router)
simply by specifying the interface, i.e., they should only be
processed by the ingress router, and no other. Hopefully that will do
the trick.

Sam90
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables question adam Linux Networking 1 07-13-2005 07:14 PM
IPTables Question James Purser Linux Networking 2 11-29-2004 06:15 PM
How to handle TCP checksum, if adapter support TCP checksum offloading? Rajesh Gupta Windows Networking 0 08-02-2004 11:20 PM
iptables question. Gabolander Linux Networking 0 10-06-2003 06:59 PM
IPTables question kza@wah.ath.cx Linux Networking 1 07-09-2003 04:34 AM



1 2 3 4 5 6 7 8 9 10 11