Message ID | 20240926110717.102194-7-pablo@netfilter.org (mailing list archive) |
---|---|
State | Accepted |
Commit | aa758763be6ddcc1c500c6e4e8a15d604e8eadba |
Delegated to: | Netdev Maintainers |
Headers | show |
Series | [net,01/14] netfilter: nf_nat: don't try nat source port reallocation for reverse dir clash | expand |
diff --git a/Documentation/networking/tproxy.rst b/Documentation/networking/tproxy.rst index 00dc3a1a66b4..7f7c1ff6f159 100644 --- a/Documentation/networking/tproxy.rst +++ b/Documentation/networking/tproxy.rst @@ -17,7 +17,7 @@ The idea is that you identify packets with destination address matching a local socket on your box, set the packet mark to a certain value:: # iptables -t mangle -N DIVERT - # iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT + # iptables -t mangle -A PREROUTING -p tcp -m socket --transparent -j DIVERT # iptables -t mangle -A DIVERT -j MARK --set-mark 1 # iptables -t mangle -A DIVERT -j ACCEPT