http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=447
Summary: dom0 netfilter DNAT rule that rewrites the destination
port doesn't work with domU TX checksum offload
Product: Xen
Version: 3.0-testing
Platform: x86-64
OS/Version: Linux-2.6
Status: NEW
Severity: normal
Priority: P2
Component: Unspecified
AssignedTo: xen-...@lists.xensource.com
ReportedBy: mgoo...@csua.berkeley.edu
A rule like this in dom0:
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination
$DOMU_IP:7800
doesn't work unless in the domU, I run:
ethtool -K eth0 tx off
If the DNAT rule preserves the destination port, it works.