[tproxy] tproxy in newer 2.6 kernels

Jan Engelhardt jengelh at linux01.gwdg.de
Sun Jul 23 17:53:13 CEST 2006

>> Of course, it's not giving the real IP address, but at least some
>> address that remains the same over time.
>Sorry, what do you mean by this?
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface   U     0      0      0   eth1   U     0      0      0   eth2         UG    0      0      0   eth1

iptables -t nat -A POSTROUTING -i eth2 -o eth1 \
	-j NETMAP --to-dest
iptables -t nat -A POSTROUTING -s -o eth1 -m owner \
	--uid-owner squid -j SNAT --to-source

The latter... it does not SNAT to the "real" address (i.e. 
might get instead of, but it suffices.

Jan Engelhardt

More information about the tproxy mailing list