From owner-freebsd-questions@FreeBSD.ORG Mon Jan 24 07:55:55 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A84F116A4CE for ; Mon, 24 Jan 2005 07:55:55 +0000 (GMT) Received: from nagual.st (cc20684-a.assen1.dr.home.nl [217.122.132.217]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3A0D043D2F for ; Mon, 24 Jan 2005 07:55:55 +0000 (GMT) (envelope-from dick@nagual.st) Received: from localhost (localhost [127.0.0.1]) (uid 1000) by nagual.st with local; Mon, 24 Jan 2005 08:55:54 +0100 Date: Mon, 24 Jan 2005 08:55:54 +0100 To: freebsd-questions Message-ID: <20050124075554.GA1535@nagual.st> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Content-Disposition: inline User-Agent: Mutt/1.5.6+20040907i From: dick hoogendijk Subject: ipf ipnat ftp question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 24 Jan 2005 07:55:55 -0000 I want ftp services to and from the internet for my gateway and my lan machines. I read the handbook but still have some questions. As I understand I have to put two lines into my ipf.rules whe I use the IPNAT built in ftp proxy. #pass out quick on rl0 proto tcp from any to any port = 21 flags S keep state # Allow in non-secure FTP ( both passive & active modes) #pass in quick on rl0 proto tcp from any to any port = 21 flags S keep state But I don't understand the proxy rules ;-( !! What happens with the /29 thing? ??? Why isn't it /24 ?? Please give me some hints on this. ######################## ### ip.nat.rules ####################### # This rule will handle all the traffic for the internal LAN: # map rl0 192.168.11.0/29 -> 0/32 proxy port 21 ftp/tcp # This rule handles the FTP traffic from the gateway. # map rl0 0.0.0.0/0 -> 0/32 proxy port 21 ftp/tcp # This rule handles all non-FTP traffic from the internal LAN. # map rl0 192.168.11.0/29 -> 0/32 # Only one filter rule is needed for FTP if the NAT FTP proxy is used. -- dick -- http://www.nagual.st/ -- PGP/GnuPG key: F86289CE ++ Running FreeBSD 4.10 ++ Debian GNU/Linux (Woody) + Nai tiruvantel ar vayuvantel i Valar tielyanna nu vilya