[tproxy] tproxy setup resulting in martian logging

Igmar Palsenberg maillist@jdimedia.nl
Mon, 2 Aug 2004 22:45:09 +0200 (CEST)


I've got a 2.4.26 kernel with grsec + openswan + tproxy support. I want to 
redirect specific destinations to a proxy on the local machine. An example 

redirect all trafic to port 12345 to the proxy on The 
iptables rule :

iptables -t tproxy -A PREROUTING -p tcp -d --dport 12345 -j 
TPROXY --on-port 12345 --on-ip

Doing a telnet to some IP on port 12345 results in :

Aug  2 21:43:28 fw kernel: martian destination from, 
dev eth1

where is the machine initiating the telnet, is the 
machine where the packet enters the IP stack on eth1.

The relevant function in this case seems to be ip_route_input_slow() in 
net/ipv4/route.c. The behaviour is logical, but prevents tproxy support 
from working in this case.

Any suggestions ???