Re: Adding SNAT support to LVS/NAT

To: Simon Horman <horms@xxxxxxxxxxxx>
Subject: Re: Adding SNAT support to LVS/NAT
Cc: Julius Volz <juliusv@xxxxxxxxxx>, lvs-devel@xxxxxxxxxxxxxxx, netdev@xxxxxxxxxxxxxxx, j.stubbs@xxxxxxxxxxxxxxx, Siim Põder <siim@xxxxxxxxxxxxxxx>
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Mon, 15 Sep 2008 08:24:38 -0700 (PDT)
On Mon, 15 Sep 2008, Simon Horman wrote:

Well, it would be a problem if it gets DNATed a second time.

Are you just being really safe? Are you trying to prevent someone from adding DNAT rules to OUTPUT?

Would it be better (as much as possible) for LVS to appear to be just another netfilter module, in which case if someone wants to DNAT in OUTPUT, this should be allowed (whether it's sensible or not). Currently LVS-NAT doesn't allow SNAT on OUTPUT, which no-one thought about when LVS-NAT was first written and it turns out to be useful.


