Browse Source

[NETFILTER]: ip_nat_tftp: Fix expectation NAT

When a TFTP client is SNATed so that the port is also changed, the
port is never changed back for the expected connection.

Signed-off-by: Marcus Sundberg <marcus@ingate.com>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Marcus Sundberg 19 years ago
parent
commit
2f9616d4c4
1 changed files with 4 additions and 1 deletions
  1. 4 1
      net/ipv4/netfilter/ip_nat_tftp.c

+ 4 - 1
net/ipv4/netfilter/ip_nat_tftp.c

@@ -42,7 +42,10 @@ static unsigned int help(struct sk_buff **pskb,
 			 enum ip_conntrack_info ctinfo,
 			 enum ip_conntrack_info ctinfo,
 			 struct ip_conntrack_expect *exp)
 			 struct ip_conntrack_expect *exp)
 {
 {
-	exp->saved_proto.udp.port = exp->tuple.dst.u.tcp.port;
+	struct ip_conntrack *ct = exp->master;
+
+	exp->saved_proto.udp.port
+		= ct->tuplehash[IP_CT_DIR_ORIGINAL].tuple.src.u.udp.port;
 	exp->dir = IP_CT_DIR_REPLY;
 	exp->dir = IP_CT_DIR_REPLY;
 	exp->expectfn = ip_nat_follow_master;
 	exp->expectfn = ip_nat_follow_master;
 	if (ip_conntrack_expect_related(exp) != 0)
 	if (ip_conntrack_expect_related(exp) != 0)