From owner-freebsd-security Wed Jul 26 0:20:13 2000 Delivered-To: freebsd-security@freebsd.org Received: from mail.rdc1.il.home.com (ha1.rdc1.il.home.com [24.2.1.66]) by hub.freebsd.org (Postfix) with ESMTP id 6044737BFAC for ; Wed, 26 Jul 2000 00:20:08 -0700 (PDT) (envelope-from stephen@math.missouri.edu) Received: from math.missouri.edu ([24.12.197.197]) by mail.rdc1.il.home.com (InterMail vM.4.01.03.00 201-229-121) with ESMTP id <20000726072007.CURR23923.mail.rdc1.il.home.com@math.missouri.edu>; Wed, 26 Jul 2000 00:20:07 -0700 Message-ID: <397E9127.D2E661C2@math.missouri.edu> Date: Wed, 26 Jul 2000 02:20:07 -0500 From: Stephen Montgomery-Smith X-Mailer: Mozilla 4.72 [en] (X11; I; Linux 2.2.14 i686) X-Accept-Language: en MIME-Version: 1.0 To: cjclark@alum.mit.edu Cc: Mike Hoskins , freebsd-security@FreeBSD.ORG Subject: Re: Problems with natd and simple firewall References: <397D4062.4A1FFFE2@math.missouri.edu> <20000725235508.D307@pool0460.cvx20-bradley.dialup.e> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org "Crist J. Clark" wrote: > > On Tue, Jul 25, 2000 at 12:23:15PM -0700, Mike Hoskins wrote: > > On Tue, 25 Jul 2000, Stephen Montgomery-Smith wrote: > > > > > > ${fwcmd} add deny all from any to 192.168.0.0/16 via ${oif} > > > > $fwcmd add divert natd all from any to any via ${natd_interface} > > > Yes, I had the same idea over dinner. Trouble is, it doesn't work. > > > I tried it. > > Sorry guys - I must have made a mistake. It does seem to work now that I try it. Maybe I made a typo somewhere. Without dynamic rules, this really seems the best solution to me. -- Stephen Montgomery-Smith Department of Mathematics, University of Missouri, Columbia, MO 65211 Phone 573-882-4540, fax 573-882-1869 http://www.math.missouri.edu/~stephen stephen@math.missouri.edu To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message