Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Dec 2000 20:20:47 -0600
From:      "Terry" <freebsd@themail.net>
To:        <freebsd-questions@FreeBSD.ORG>
Subject:   natd on inside interface
Message-ID:  <000901c05ff4$52d93740$0200a8c0@texhoma.net>

next in thread | raw e-mail | index | archive | help
I have a FreeBSD 4.1 server used primarily as a firewall (with three
non-dialup ethernet interfaces).  Natd is configured and working on the
outside interface.  I need to run a second instance of natd on an inside
interface, but have been unsuccessful so far.

I defined "natd2" as a service on port 8669 in /etc/services, edited
rc.firewall to divert the desired traffic associated with the interface,
defined a script to start the second natd as follows:

/sbin/natd -v -n fxp0 -reverse -p natd2

The system shows that it translates addresses as it should for traffic
coming in from fxp0, but traffic does not get translated coming back through
the interface.  IE if I ping a second interface in the server from a machine
attached to fxp0, the monitor shows traffic coming in, shows the expected
translation, but never shows any response back out through fxp0.

The first instance of natd (on the default port 8668) continues to work
correctly and the vpn through an outside interface continues to function
properly.

Any examples or success stories of natd configuration using the -reverse
option would be greatly appreciated.

Terry



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?000901c05ff4$52d93740$0200a8c0>