Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #174642

Re: iptables question

From Joe <joe@jretrading.com>
Newsgroups linux.debian.user
Subject Re: iptables question
Date 2016-11-13 13:40 +0100
Message-ID <sD2eJ-fK-15@gated-at.bofh.it> (permalink)
References <sCNSp-7BL-15@gated-at.bofh.it> <sCP7P-8pY-13@gated-at.bofh.it> <sCZqx-6Me-11@gated-at.bofh.it> <sCZTz-7fH-21@gated-at.bofh.it> <sD0mB-7qR-7@gated-at.bofh.it>
Organization JRE Trading Ltd

Show all headers | View raw


On Sun, 13 Nov 2016 11:29:48 +0100
Pascal Hambourg <pascal@plouf.fr.eu.org> wrote:

> Le 13/11/2016 à 11:09, Joe a écrit :
> > Pascal Hambourg <pascal@plouf.fr.eu.org> wrote:
> >  
> >> Le 12/11/2016 à 23:32, Joe a écrit :  
> >>>
> >>> The SNAT should not be an issue, it can handle all protocols
> >>> transparently  
> >>
> >> No it cannot. NAT is not possible with some IP protocols. Plain
> >> IPSec (without NAT-T encapsulation) is the first one that comes in
> >> mind.  
> >
> > I used to have a fair bit to do with PPTP through three or four
> > NATs,  
> 
> PPTP rather falls into the "complex protocols" described below.

Exactly so. You wouldn't believe how many routers of ten years ago or
so didn't handle it properly, at least with their initial firmware. But
it still doesn't need any additional NAT rules in iptables, the single
SNAT rule handles it, as well as tcp, udp etc. Other rules are needed
for correct *operation*, but not for NAT. Yes, I'm aware that NAT stops
plain IPSec working, as the endpoint IP addresses are involved in the
encryption. That isn't an iptables rule issue, and our single SNAT
rule will forward Protocol 47 and 50 just as easily as Protocol 6.

> 
> >> Also many complex protocols such as FTP or SIP (nothing exotic
> >> here) require special support and this is not transparent as it
> >> requires messing with the payload, not only with the packet
> >> headers. Use of encryption with these protocoles may come in the
> >> way and defeat NAT handling.  
> >
> > Is ssh really a more difficult protocol to handle than http?  
> 
> No. SSH relies on a single TCP connection, like TCP and other
> "simple" protocols. I reacted to you writing "NAT can handle *all*
> protocols *transparently*".
> 
> > I'm using 'protocol' in
> > the small-p sense, not referring specifically to Internet
> > Protocols.  
> 
> What is the "small-p sense" ?
> 

In the sense of 'a defined system for data transfer', as opposed to the
Internet Protocols of tcp, udp, gre etc. http is spoken of as a
'protocol', small-p, although it is a tiny subset of the tcp Internet
Protocol. Many people used to confuse tcp port 47 with IP 47, to the
extent that some router firmware would forward IP 47 if asked for
tcp/47, which only perpetuated the confusion.

-- 
Joe

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

iptables question deloptes <deloptes@gmail.com> - 2016-11-12 22:20 +0100
  Re: iptables question Joe <joe@jretrading.com> - 2016-11-12 23:40 +0100
    Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 01:30 +0100
      Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:50 +0100
      Re: iptables question Michael Milliman <michael.e.milliman@gmail.com> - 2016-11-13 12:40 +0100
        Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 16:10 +0100
          Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 18:00 +0100
            Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 20:50 +0100
              Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 21:20 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 21:50 +0100
                Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-13 22:50 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
                Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-14 00:30 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 00:50 +0100
                Re: iptables question Henning Follmann <hfollmann@itcfollmann.com> - 2016-11-14 13:10 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 20:20 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 01:00 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-14 23:10 +0100
      Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:10 +0100
        Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 08:20 +0100
          Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 09:10 +0100
    Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:40 +0100
      Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 11:10 +0100
        Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 11:40 +0100
          Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 13:40 +0100
            Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 15:00 +0100
              Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:00 +0100

csiph-web