From owner-freebsd-questions@FreeBSD.ORG Thu May 8 06:34:11 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2746C37B401 for ; Thu, 8 May 2003 06:34:11 -0700 (PDT) Received: from empire.explosive.mail.net (empire.explosive.mail.net [205.205.25.120]) by mx1.FreeBSD.org (Postfix) with SMTP id 2B17043F75 for ; Thu, 8 May 2003 06:34:10 -0700 (PDT) (envelope-from mykroft@explosive.mail.net) Received: (qmail 30956 invoked from network); 8 May 2003 13:34:17 -0000 Received: from ticking.explosive.mail.net (HELO ticking) (205.205.25.116) by empire.explosive.mail.net with SMTP; 8 May 2003 13:34:17 -0000 Message-ID: <005501c31566$98052f70$7419cdcd@ticking> From: "Adam Maas" To: "Wayne Swart" , "FreeBSD Mailing list" References: <20030508142730.V8587-100000@gemini.fixx.co.za> Date: Thu, 8 May 2003 09:34:47 -0400 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2720.3000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Subject: Re: ipfw + natd X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 08 May 2003 13:34:11 -0000 ----- From: "Wayne Swart" To: "FreeBSD Mailing list" Sent: Thursday, May 08, 2003 8:31 AM Subject: ipfw + natd > Lo > > I am running FreeBSD4.8-RELEASE and have a problem with ipfw and natd. > > the two interfaces (dc0 and dc1) have the following ip setup. > > dc1 ip: 10.10.10.1 > dc0 ip: 196.x.x.x > > now i can't do any requests through my box to "the outside" anymore, since > i added a default to deny rule. > > i use the following ipfw rules for the nat, but it does not seem to have > any impact on the requests that has to go through it. > > ipfw add divert natd all from any to any via dc0 out keep-state > ipfw add allow all from 10.10.10.0/24 to any via dc0 out keep-state > ipfw add allow all from 10.10.10.0/24 to any via dc1 in keep-state > > is there an easier way to troubleshoot this? > Could we see the results of an 'ipfw list'? Sounds like the Default Deny rule is first rather than last on the list of ipfw rules. Adam