POSTROUTING NAT doesn't operate on ISAKMP traffic
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Expired
|
Undecided
|
Unassigned |
Bug Description
I have a Juniper firewall (SSG-5) that does ISAKMP with NAT behind my linux server. This works with the following iptables rule under linux-2.6.32.-24:
iptables -t nat -A POSTROUTING -s <my private network> -o eth1 -j SNAT --to <my public static IP>
Under linux-2.6.32-25, the NAT rule shows up in the listing of "iptables -t nat -nvL", but it fails to do a source translation. My private network, an RFC 1918 non-routable network, simply leaks out my public interface (confirmed by a tshark trace) and my ISP simply drops the packets.
ProblemType: Bug
DistroRelease: Ubuntu 10.04
Package: linux-image-
Regression: Yes
Reproducible: Yes
ProcVersionSign
Uname: Linux 2.6.32-24-generic x86_64
NonfreeKernelMo
AlsaVersion: Advanced Linux Sound Architecture Driver Version 1.0.21.
Architecture: amd64
AudioDevicesInUse:
USER PID ACCESS COMMAND
/dev/snd/
/dev/snd/pcmC0D0p: derek 3777 F...m pulseaudio
CRDA: Error: [Errno 2] No such file or directory
Card0.Amixer.info:
Card hw:0 'SB'/'HDA ATI SB at 0xfe024000 irq 16'
Mixer name : 'Realtek ALC889A'
Components : 'HDA:10ec0885,
Controls : 43
Simple ctrls : 24
Card1.Amixer.info:
Card hw:1 'CX8801'/'Conexant CX8801 at 0xf8000000'
Mixer name : 'CX88'
Components : ''
Controls : 3
Simple ctrls : 2
Date: Sun Oct 3 17:08:36 2010
HibernationDevice: RESUME=
MachineType: Gigabyte Technology Co., Ltd. GA-MA69G-S3H
ProcCmdLine: BOOT_IMAGE=
ProcEnviron:
PATH=(custom, user)
LANG=en_US.utf8
SHELL=/bin/bash
RelatedPackageV
RfKill:
SourcePackage: linux
WpaSupplicantLog:
dmi.bios.date: 12/29/2008
dmi.bios.vendor: Award Software International, Inc.
dmi.bios.version: F7
dmi.board.name: GA-MA69G-S3H
dmi.board.vendor: Gigabyte Technology Co., Ltd.
dmi.chassis.type: 3
dmi.chassis.vendor: Gigabyte Technology Co., Ltd.
dmi.modalias: dmi:bvnAwardSof
dmi.product.name: GA-MA69G-S3H
dmi.sys.vendor: Gigabyte Technology Co., Ltd.
Changed in linux (Ubuntu): | |
status: | New → Confirmed |
Just FYI, I ran apport after I had rebooted back to 2.6.32-24, so I just realized that some of the debug dumps are probably invalid.