Networking Forums  

Go Back   Networking Forums > Networking Newsgroups > Linux Networking

Iptables checksum question

Reply
 
Thread Tools Display Modes
  #1  
Old 07-27-2004, 02:30 AM
Default Iptables checksum question



Hi,

Iptables question: we've managed to get ip tables working on the
ingress router to the extent that it modifies QOS bits on the IP
header as desired if the destination port is a match to the iptables
command. We'd like to have this work both ways - i.e. put communiction
over a particular port in a special diffserv class. However, when we
add the same iptables command to the egress router, the checksum is
incorrect when it arrives at the end host (Ethereal tell us this).

Question: what are we doing wrong? Is this a bug in iptables, or more
likely a lack of understanding on our part? Any answers/help much
appreciated.

Best Regards,
Sam90


Sam
Reply With Quote
  #2  
Old 07-27-2004, 11:29 PM
Sam
Guest
 
Posts: n/a
Default Re: Iptables checksum question

(E-Mail Removed) (Sam) wrote in message news:<(E-Mail Removed). com>...
> Hi,
>
> Iptables question: we've managed to get ip tables working on the
> ingress router to the extent that it modifies QOS bits on the IP
> header as desired if the destination port is a match to the iptables
> command. We'd like to have this work both ways - i.e. put communiction
> over a particular port in a special diffserv class. However, when we
> add the same iptables command to the egress router, the checksum is
> incorrect when it arrives at the end host (Ethereal tell us this).
>
> Question: what are we doing wrong? Is this a bug in iptables, or more
> likely a lack of understanding on our part? Any answers/help much
> appreciated.
>
> Best Regards,
> Sam90


I still don't have an answer - however, I think I can avoid the
packets from getting processed twice by iptables (on in each router)
simply by specifying the interface, i.e., they should only be
processed by the ingress router, and no other. Hopefully that will do
the trick.

Sam90
Reply With Quote
Reply

Tags
checksum, iptables, question

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 03:18 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.