From owner-freebsd-questions@FreeBSD.ORG Thu Apr 8 20:43:49 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 02338106566C for ; Thu, 8 Apr 2010 20:43:49 +0000 (UTC) (envelope-from osp@aloha.com) Received: from relay.pixi.com (relay.pixi.com [206.127.224.101]) by mx1.freebsd.org (Postfix) with ESMTP id C613A8FC0C for ; Thu, 8 Apr 2010 20:43:48 +0000 (UTC) Received: from leka.aloha.com (leka.aloha.com [206.127.224.85]) by relay.pixi.com (8.13.8+Sun/8.13.6) with ESMTP id o38KhlnQ015443 for ; Thu, 8 Apr 2010 10:43:48 -1000 (HST) Received: from [66.248.53.94] (02-094.169.popsite.net [66.248.53.94]) by leka.aloha.com (8.13.8+Sun/8.12.11) with SMTP id o38KhiFi015433 for ; Thu, 8 Apr 2010 10:43:46 -1000 (HST) Message-Id: <201004082043.o38KhiFi015433@leka.aloha.com> Date: Thu, 8 Apr 2010 10:42 -1000 From: "Gary Dunn" To: "freebsd-questions" MIME-Version: 1.0 X-Mailer: Newton Mail V/5.2.1 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Subject: Re: Kernel Config for NAT X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 08 Apr 2010 20:43:49 -0000 On Thu, 8 Apr 2010 08:10:34 -0400 Robert Huff wrote: > So ... double-checking I'm doing this right: > > 1) in /boot/loader.conf: > > ipfw_load=3D"YES" > ipdivert_load=3D"YES" yes; see NAT HB 31.9.3 > > 2) in the kernel config: IMHO, and according to Adam Vandr More, kernel options are no longer = required. > > 3) in /etc/sysctl.conf: > > net.inet.ip.fw.default_to_accept=3D"1" see NAT HB 31.9.3 > net.inet.ip.fw.verbose=3D"1" > net.inet.ip.fw.verbose_limit=3D"100" see IPFW HB 30.6.1 I would use a smaller limit such as 5. > > > That cover > it? Still need entries in /etc/rc.conf. See HB 30.9.5, 30.6.3, 30.6.5.7 I also have DHCP serving the downstream (private) network. Upstream gets = configured by dhclient. -- Gary Dunn, Honolulu osp@aloha.com http://openslate.net/ http://e9erust.blogspot.com/ Sent from a Newton 2100 via Mail V