From mboxrd@z Thu Jan 1 00:00:00 1970 From: Marco Gaiarin Date: Tue, 30 Jul 2019 14:12:58 +0000 Subject: Re: Policy routing (fwmark-based) and local traffic... Message-Id: <20190730141258.GH2430@sv.lnf.it> List-Id: References: <20190730123207.GE2430@sv.lnf.it> In-Reply-To: <20190730123207.GE2430@sv.lnf.it> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable To: lartc@vger.kernel.org Mandi! Florian Westphal In chel di` si favelave... > > iptables -t mangle -I OUTPUT -d $gip -p tcp -m multiport --dports ${TC= P_PORTS} -m mark --mark 0/$MASK -j MARK --set-mark $MARK/$MASK > Works for me. Ah. For me no. Could be the kernel/iptables version? Currently: ulysses:~# uname -a Linux ulysses 3.2.0-6-686-pae #1 SMP Debian 3.2.102-1 i686 GNU/Linux ulysses:~# dpkg -l | grep iptables ii iptables 1.4.14-3.1 = i386 administration tools for packet filtering and NAT > > iptables -t mangle -I OUTPUT -d $gip -p tcp -m multiport --dports ${TC= P_PORTS} -j MARK --set-mark $MARK/$MASK > Whats an implicit mark set by the routign decision? I was only supposing... sorry... --=20 dott. Marco Gaiarin GNUPG Key ID: 240A3D66 Associazione ``La Nostra Famiglia'' http://www.lanostrafamiglia.= it/ Polo FVG - Via della Bont=E0, 7 - 33078 - San Vito al Tagliamento= (PN) marco.gaiarin(at)lanostrafamiglia.it t +39-0434-842711 f +39-0434-842= 797 Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA! http://www.lanostrafamiglia.it/index.php/it/sostienici/5x1000 (cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)