From owner-freebsd-pf@FreeBSD.ORG Sat Jul 8 19:41:41 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6C64E16A4DA for ; Sat, 8 Jul 2006 19:41:41 +0000 (UTC) (envelope-from dimas@dataart.com) Received: from relay1.dataart.com (fobos.marketsite.ru [62.152.84.30]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0240143D45 for ; Sat, 8 Jul 2006 19:41:40 +0000 (GMT) (envelope-from dimas@dataart.com) Received: from e1.universe.dart.spb ([192.168.10.44]) by relay1.dataart.com with esmtp (Exim 4.62) (envelope-from ) id 1FzIgM-000PVj-Ll; Sat, 08 Jul 2006 23:41:38 +0400 X-MimeOLE: Produced By Microsoft Exchange V6.5 Content-class: urn:content-classes:message MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Date: Sat, 8 Jul 2006 23:38:55 +0400 Message-ID: X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: proxies Thread-Index: Acaiv0ntEqRBALQURu+wVt3sI41PbQABZdLg From: "Dmitry Andrianov" To: "Gergely CZUCZY" Cc: freebsd-pf@freebsd.org Subject: RE: proxies X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 08 Jul 2006 19:41:41 -0000 > we do it a bit different way. > man ftp-proxy Well, it is _completely_ different way. It is only applicable on the gateway router (which performs NAT) but can not be used on our internal router because this way FTP server does not see client's real IP. There are two different things:=20 a) punching holes in the firewall to accept related connections b) "patching" traffic to translate Ips contained in the application level data On the NAT-less router I obviously only need first. The approach you suggesting always do both and there is no way of avoiding second. > that's for FTP, but a similar program can be constructed for different protocolls Actually, my question was if PPTP, H323 etc modules _already_ available. >From your anwser I guess no... Thanks Regards, Dmitry Andrianov