Skip to content

Commit

Permalink
[NETFILTER]: ip_nat_tftp: Fix expectation NAT
Browse files Browse the repository at this point in the history
When a TFTP client is SNATed so that the port is also changed, the
port is never changed back for the expected connection.

Signed-off-by: Marcus Sundberg <marcus@ingate.com>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
  • Loading branch information
Marcus Sundberg authored and David S. Miller committed Dec 12, 2005
1 parent 66e0522 commit 2f9616d
Showing 1 changed file with 4 additions and 1 deletion.
5 changes: 4 additions & 1 deletion net/ipv4/netfilter/ip_nat_tftp.c
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,10 @@ static unsigned int help(struct sk_buff **pskb,
enum ip_conntrack_info ctinfo,
struct ip_conntrack_expect *exp)
{
exp->saved_proto.udp.port = exp->tuple.dst.u.tcp.port;
struct ip_conntrack *ct = exp->master;

exp->saved_proto.udp.port
= ct->tuplehash[IP_CT_DIR_ORIGINAL].tuple.src.u.udp.port;
exp->dir = IP_CT_DIR_REPLY;
exp->expectfn = ip_nat_follow_master;
if (ip_conntrack_expect_related(exp) != 0)
Expand Down

0 comments on commit 2f9616d

Please sign in to comment.