Nortel Networks alteon filter question

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
alteon filter question cconnell_1 08-15-06
Posted by on August 15, 2006, 6:32 pm
Please log in for more thread options
hi,
i have to do a demo tommorrow for a transparent proxy and have a
question about a filter. Can i use a filter to do "2" things on a
packet

1) nat the source ip (i will use a static nat)
2) then redirect it to a real server group

so if a packet comes into the alteon, depending on the sip, i will nat
it, then redirect so i would have

filter 1
sip <ip>
action nat it

then

filt2
sip any
dip any
action redir (group)

I want the above to work for all packets.

I have done these things before but used another alteon to do the nat
and then when it passes it back to the 1st alteon, this redirects it to
the real server group, but never both at the same time, i.e. used one
alteon to do nat, and one to do the load balancing/redirection.

So the bottom line is does this work on the alteon? or can only one
filter action be applied per packet?

thanks


Posted by Dophi on August 15, 2006, 9:58 pm
Please log in for more thread options
Probably you can't do it becasuse there is a "stop on match" behavior
for filter.

cconnell_1@lycos.com wrote:
> hi,
> i have to do a demo tommorrow for a transparent proxy and have a
> question about a filter. Can i use a filter to do "2" things on a
> packet
>
> 1) nat the source ip (i will use a static nat)
> 2) then redirect it to a real server group
>
> so if a packet comes into the alteon, depending on the sip, i will nat
> it, then redirect so i would have
>
> filter 1
> sip <ip>
> action nat it
>
> then
>
> filt2
> sip any
> dip any
> action redir (group)
>
> I want the above to work for all packets.
>
> I have done these things before but used another alteon to do the nat
> and then when it passes it back to the 1st alteon, this redirects it to
> the real server group, but never both at the same time, i.e. used one
> alteon to do nat, and one to do the load balancing/redirection.
>
> So the bottom line is does this work on the alteon? or can only one
> filter action be applied per packet?
>
> thanks


Posted by kensampson@gmail.com on August 16, 2006, 8:36 am
Please log in for more thread options
I know you mentioned you are doing transparent proxy redir but may want
to look at PIP (proxy IP) as a method of source NAT and continue to use
a Filter for redir.

In order to use PIP you need to have a VIP with client processing
enable on the ingress port. This would no longer be transparent proxy
though.


Dophi wrote:
> Probably you can't do it becasuse there is a "stop on match" behavior
> for filter.
>
> cconnell_1@lycos.com wrote:
> > hi,
> > i have to do a demo tommorrow for a transparent proxy and have a
> > question about a filter. Can i use a filter to do "2" things on a
> > packet
> >
> > 1) nat the source ip (i will use a static nat)
> > 2) then redirect it to a real server group
> >
> > so if a packet comes into the alteon, depending on the sip, i will nat
> > it, then redirect so i would have
> >
> > filter 1
> > sip <ip>
> > action nat it
> >
> > then
> >
> > filt2
> > sip any
> > dip any
> > action redir (group)
> >
> > I want the above to work for all packets.
> >
> > I have done these things before but used another alteon to do the nat
> > and then when it passes it back to the 1st alteon, this redirects it to
> > the real server group, but never both at the same time, i.e. used one
> > alteon to do nat, and one to do the load balancing/redirection.
> >
> > So the bottom line is does this work on the alteon? or can only one
> > filter action be applied per packet?
> >
> > thanks


Similar ThreadsPosted
alteon filter question August 15, 2006, 6:32 pm
Alteon tsdump question April 12, 2005, 7:58 pm
alteon sync question July 13, 2006, 1:38 pm
Nortel 470 IP Filter Configuration. March 10, 2008, 1:04 pm
Alteon AD4 Web Switch March 9, 2005, 8:59 pm
Alteon AD3 and WEBDAV September 24, 2005, 8:02 pm
Alteon binary images. May 15, 2005, 10:34 pm
Alteon AD4 configuration problem September 21, 2005, 3:38 pm
Alteon config needed March 7, 2006, 7:09 pm
alteon and vrrp failover April 19, 2006, 12:57 pm
alteon hash metric May 22, 2006, 9:38 pm
Alteon WebOS Images? July 19, 2006, 12:37 pm
Alteon 180 OS and GSLB keys March 7, 2007, 6:40 am
alteon 184 layer 7 performances December 16, 2005, 5:30 am
Alteon 180e VIP Problem December 21, 2005, 6:06 am