Re: nftables: masquerade sets wrong source address

2016-12-18 Thread Liping Zhang
2016-12-17 22:18 GMT+08:00 Liping Zhang : > > For loopback connection, the request packets will traverse: > OUTPUT->POSTROUTING->PREROUTING->INPUT > and the source ip will be modified in nat POSTROUTING hook. > > Meanwhile the reply packets will also traverse: > OUTPUT->POSTROUTING->PREROUTING->INP

Re: [PATCH net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP

2016-12-18 Thread Marcelo Ricardo Leitner
On Thu, Dec 15, 2016 at 12:31:40PM +0800, Xin Long wrote: > Now when adding an ipt_CLUSTERIP rule, it only checks duplicate config in > clusterip_config_find_get(). But after that, there may be still another > thread to insert a config with the same ip, then it leaves proc_create_data > to do dupli