Re: [tproxy,regression] tproxy broken in 2.6.32
From: jamal <hidden>
Date: 2009-11-27 16:05:28
On Fri, 2009-11-27 at 09:26 +0100, KOVACS Krisztian wrote:
Hi, On Thu, 2009-11-26 at 18:19 +0100, Andreas Schultz wrote:quoted
Hi, git bisect shows that TPROXY has been broken by commit f7c6fd2465d8e6f4f89c5d1262da10b4a6d499d0, [PATCH] net: Fix RPF to work with policy routing I had a look at the patch, and it seems logical that this would break TPROXY.Indeed, that's a good catch. If this is indeed the problem you should be able to work it around by disabling rpfilter on the ingress interface. Does it work that way?
Not familiar with tproxy, but I suspect the system doesnt see the mark before policy routing happens. So probably the wrong route cache gets created. Easy to validate by dumping the route cache. If thats so, you have to set the mark in pre-route hook if it uses iptables. cheers, jamal