[lug] Iptables

Zan Lynx zlynx at acm.org
Thu Aug 3 16:37:58 MDT 2006


You probably have a DROP rule somewhere, or as a chain default.  I
always put a LOG target just ahead of any DROP (at least at first until
I get tired of the spam) so that I can see what is happening.

You can see if DROPs are getting hit just by redirecting the iptables
output to a temporary file, then do some network traffic, then dump to
another temporary file, then diff the two files.

On Thu, 2006-08-03 at 15:20 -0600, Dan Ferris wrote:
> Hello list,
> 
> I have the following in an iptables setup:
[snip]
> 
> Of course, the issue is that NOTHING will NAT properly.  In fact, those 
> rules are NEVER hit at all.  I watch with a sniffer and I can see the 
> traffic come into the proper interfaces, but nothing ever happens.  This 
> problem is getting very confusing and frustrating, so any suggestions 
> would be appreciated.
-- 
Zan Lynx <zlynx at acm.org>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://lists.lug.boulder.co.us/pipermail/lug/attachments/20060803/80f8d650/attachment.pgp>


More information about the LUG mailing list