[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Fwmark and iproute2




-----Original Message-----
From: Mike Mestnik <cheako911@yahoo.com>
To: R.DElia@starcomitalia.com, debian-firewall@lists.debian.org
Date: Fri, 12 Nov 2004 15:36:58 -0800 (PST)
Subject: Re: Fwmark and iproute2

> Hey,
>
> > I need to sent local generated packets through one or the other
> gateway
> > using fwmark rules.
>
> As far as I know  fwmark only works inside the kernel. So maybe you
> should
> take a look at DSCP.

Fwmark or TOS doesn't matter: the problem is the same. When packets reachs
netfilter's code, the outgoing interface is already choosen.

 
> > Unfortunately the outgoing interface is choosen before entering the
> > mangle table...
>
> ?
> Do you know the picture from:
> http://iptables-tutorial.frozentux.net/iptables-tutorial.html#TRAVERSIN
> GGENERAL

Local processes -> Routing Decision -> mangle OUTPUT (too late...)

THIS is the problem...;)

Radel



Reply to: