I'm using kernel 2.4.37 and iptables 1.3.8.
I have a complex firewall requirement - what I need is to do DNAT
without it creating an entry in the connection tracking table. Is
there a module or command which does this?
Alternatively, is there an iptables module which allows just the
destination port of packets to be changed, without anything being
written to connection tracking?
(DNAT has a feature/bug: if you establish a DNAT connection in
response to an iptables rule which depends on the *interface* of the
incoming packet, the connection which is created will have no concept
of the interface.
Thus, if a packet is DNATted (as a result of an iptables rule matching
its source interface of eth0), packets with identical addresses and
ports will also be DNATted, even if they *didn't* come in from eth0!
This breaks an HA system which used to work with ipchains.)