Commit ce518710 authored by Brian May's avatar Brian May

Add to TPROXY documentation

parent bdc7d3a9
...@@ -88,9 +88,14 @@ There are some things you need to consider for TPROXY to work: ...@@ -88,9 +88,14 @@ There are some things you need to consider for TPROXY to work:
Otherwise sshuttle may attempt to intercept the ssh packets, which will not Otherwise sshuttle may attempt to intercept the ssh packets, which will not
work. Use the `--exclude` parameter for this. work. Use the `--exclude` parameter for this.
4. You do need the `--method=tproxy` parameter, as above. 4. Similarly, UDP return packets (including DNS) could get intercepted and
bounced back. This is the case if you have a broad subnet such as
``0.0.0.0/0`` that includes the IP address of the client. Use the
`--exclude` parameter for this.
5. The routes for the outgoing packets must already exist. For example, if your 5. You do need the `--method=tproxy` parameter, as above.
6. The routes for the outgoing packets must already exist. For example, if your
connection does not have IPv6 support, no IPv6 routes will exist, IPv6 connection does not have IPv6 support, no IPv6 routes will exist, IPv6
packets will not be generated and sshuttle cannot intercept them:: packets will not be generated and sshuttle cannot intercept them::
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment