Re: NAT to a broadcast addess using iptables?




Pascal Hambourg wrote:
Hello,

news@xxxxxxxxxxxxxxxxxx a écrit :

Oh, so you're looking for iptables gurus... then don't bother to read my
reply.

LOL


Netfilter/iptables itself does not care whether an IP addresse is a
broadcast or unicast address (which can cause trouble with connection
tracking). But in the Linux kernel IP stack, the DNAT operation in the
PREROUTING chain takes place before the input routing decision is taken.
So the input routing algorithm receives a packet with a broadcast
destination address, but it won't forward such packets. Broadcast
packets can only be sent or received locally, not forwarded.

(Yes, I know it's insane, but is it possible!?)

I'm afraid it is not possible to do this with iptables. Is your goal to
do some kind of remote wake-on-LAN ?

Indeed it is - exactly that.

.



Relevant Pages

  • RE: iptables and/or CUPS question
    ... is the broadcast address for the 10.x.x.x series of ... something from 10.1.4.238 (a different network) that is an invalid ... It looked like iptables on my box was stopping ... packets from itself, so I bumped up the detail to Med, and got this: ...
    (RedHat)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (comp.os.linux.x)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (comp.os.linux.setup)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (alt.linux)
  • X & Gnome crashes the system with iptables
    ... kernel 2.4.21, ... I spent a lot of time to write rules for iptables to obtain a good firewall. ... # Support for connection tracking ... packets are denied until ...
    (comp.os.linux.security)