Re: strange nat behaviour

On Mon, May 07, 2001 at 01:24:23AM +0200, Michel Decima wrote:
> I'm using a linux box with netfilter to masquerade my home LAN
> and I have (very) strange behaviour whith some web sites: They
> are not reachable by the masqueraded workstation (but I can read
> them from the firewall). After the browser says 'connected to X'
> the connections stalls. I've checked the ECN feature, and it is
> not compiled in the kernel.

It's not immediately apparent to me what the problem is; however I would
suggest hooking up Ethereal or tcpdump and taking a look at the traffic
coming back from the unreachable site(s).

Perhaps some TCP options are being set that are not being allowed
through your firewall for some reason.  There must be _something_
different about the traffic and it should be fairly easy to find out
what it is.


Jim B.

