Richard Chan richard at treeboxsolutions.com
Sat Nov 5 18:01:57 CET 2016

Hi, in the roadwarrior configuration, from a conceptual point of view, why
doesn't table 220 change the source IP address of forwarded packets (say
the roadwarrior has a subnet behind it)?

# ip ro sho table 220 via dev eth0  proto static  src

# ip rule show
0:      from all lookup local
220:    from all lookup 220
32766:  from all lookup main
32767:  from all lookup default

roadwarrior has a separate subnet and is forwarding/NAT'ing
packets.  When  I ping a host on the central site LAN

- OUTPUT chain sees the source IP address as (table 220 is
-  FORWARD chain sees the source IP address as 192.168.2.X  (host cannot be
reached until these packets are SNAT'ed to

