Re: iptables NAT entry times out but connects from firewall

Harald Welte (laforge@netfilter.org)
Tue, 29 Apr 2003 21:07:13 +0200


This is a MIME-formatted message. If you see this text it means that your
E-mail software does not support MIME-formatted messages.

--=_courier-31908-1051643525-0001-2
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Apr 28, 2003 at 12:57:16PM -0500, Hanasaki JiJi wrote:
> There is a firewall with two NICs and the below rule to allow an=20
> internal host to connect out to smtp servers on the internet. Some=20
> hosts have a connection timeout on a connect from $INTERNAL_IP_OF_SMTP=20
> yet connect from the firewall just fine.

this seems to be an iptables usage problem, please follow-up to the
netfilter mailinglist at netfilter@lists.netfilter.org.

for more information, plaese see the netfilter homepage at
http://www.netfilter.org

--=20
- Harald Welte <laforge@netfilter.org> http://www.netfilter.org/
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D
"Fragmentation is like classful addressing -- an interesting early
architectural error that shows how much experimentation was going
on while IP was being designed." -- Paul Vixie

--=_courier-31908-1051643525-0001-2
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE+rs1hXaXGVTD0i/8RAkbtAJ94IfElgwzLq7iL9FQEv1DnH//wcgCffgMT
WCGPatZeSMfneeROgbHDMJ0=
=/qi8
-----END PGP SIGNATURE-----

--=_courier-31908-1051643525-0001-2--