iptables trick for when you have an interface with a dynamic IP that is not your default gateway, but you want inbound port-forwarded traffic to still route properly. iptables -t mangle -D PREROUTING -m conntrack --ctstate DNAT -j MARK --set-mark 10 (+ usual route fwmark stuff)
-
-
Incidentally, even though the Ralink hw_nat module is open source (the Cavium equivalent isn't...), I haven't been able to find where in the code it determines what firewall rules disable the fastpath. Still looking...
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.