On Saturday 23 Feb 2013 16:09:52 Tom Eastep wrote: > > Note: Netfilter does not support IPv6 MASQUERADE, so you must > specify one or more addresses in the ADDRESSES column. In view of > this restriction, IPv6 SNAT is defined in a file named > /etc/shorewall6/snat rather than /etc/shorewall6/masq.
Tom Kernel 3.8 has config. option CONFIG_IP6_NF_TARGET_MASQUERADE Shorewall6 snat entry: eth0 2001:2::/56 :random Produces ip6tables rule: -A eth0_masq -s 2001:2::/56 -j MASQUERADE --random Which ip6tables-restore accepts. I am using ip6tables 1.4.17. Note, kernel 3.7 also has the above config. option, but I haven't tried it. Steven. ------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_feb _______________________________________________ Shorewall-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-devel
