Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 22 Dec 1998 12:23:13 -0500 (EST)
From:      "Stan Brown" <stanb@awod.com>
To:        net@FreeBSD.ORG
Subject:   Help with NAT, and a firewall
Message-ID:  <199812221723.JAA19777@hub.freebsd.org>

next in thread | raw e-mail | index | archive | help
	I am trying to set up a FFreebSD 2.2.6 machine to server as a
	communication gateway for my local network. I have a canle modem which
	is conected to the FreebSD box using a second ethernet card. I am using
	NAT to allow the other machines on my network to access the outside
	world. 

	All this works fine, using the ipfw rules sugested in the NAt man page.
	However since this is a full time connections, with a fixed IP address,
	I am feeeling a bit paranoid.

	I would like to set up a reasonable set of firewall rules for ipfw. I
	started witht eh default /etc/rc.firewall, but it was not very usefeul.
	I think I have worked through most of what I need, but I am having
	problems with NAT being denied permission to write back packets it has
	translated. 

	Could someone sugest a rule to allow NAT to work with a firewalled
	system?

	I would alos be interested in seeing other peoples firewall rules for
	similat systesm. No sense in being hacked, because I am unwilling to
	lear from others experience, is there?

	Any advice welcom.

-- 
Stan Brown     stanb@netcom.com                                    770-996-6955
Factory Automation Systems
Atlanta Ga.
-- 
Windows 98: n.
	minor patch release for 32-bit extensions and a graphical shell for a
	16-bit patch to an 8-bit operating system originally coded for a 4-bit
	microprocessor, written by a 2-bit company that can't stand for 1 bit
	of competition.
-
(c) 1998 Stan Brown.  Redistribution via the Microsoft Network is prohibited.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-net" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199812221723.JAA19777>