On Saturday 23 Feb 2013 16:09:52 Tom Eastep wrote:
> 
>     Note: Netfilter does not support IPv6 MASQUERADE, so you must
>     specify one or more addresses in the ADDRESSES column. In view of
>     this restriction, IPv6 SNAT is defined in a file named
>     /etc/shorewall6/snat rather than /etc/shorewall6/masq.

Tom

Kernel 3.8 has config. option CONFIG_IP6_NF_TARGET_MASQUERADE

Shorewall6 snat entry:

eth0  2001:2::/56  :random

Produces ip6tables rule:

-A eth0_masq -s 2001:2::/56 -j MASQUERADE --random

Which ip6tables-restore accepts.

I am using ip6tables 1.4.17.

Note, kernel 3.7 also has the above config. option, but I haven't tried it.
 
Steven.

------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_feb
_______________________________________________
Shorewall-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-devel

Reply via email to