Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 03 Aug 2002 12:21:00 -0700
From:      Michael Sierchio <>
Cc:        "Crist J. Clark" <cjc@FreeBSD.ORG>, FBIPFW <>,,,,,,,,
Subject:   Re: natd & keep-state
Message-ID:  <>
References:  <>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help
Joe & Fhe Barbish wrote:
> So Crist we meet again. 

[scads of drivel deleted]

As Crist stated, ipfw stateful rules and natd aren't inherently
compatible, but it is possible to use them together.  This is
facilitated by using at least two IP addresses on the outside
interface, and some non-intuitive rules.

A brief snippet:


fw="/sbin/ipfw -q"

# some rules skipped for this example

#note the asymmetry

$fw add 02000 divert natd ip from any to $ipaddr2 in recv $oif
$fw add 02000 divert natd ip from any to any out xmit $oif

$fw add 02400 check-state

$fw add 02500 allow icmp from any to any icmptype 0,3,8,11

# natd is invoked with 'deny_incoming'

$fw add 02620 allow ip from $ipaddr2 to any
$fw add 02630 allow ip from any to $ipaddr2

$fw add 05800 allow udp from $ipaddr1 to any keep-state
$fw add 05900 allow tcp from $ipaddr1 to any setup keep-state

$fw add 65000 deny ip from any to any

To Unsubscribe: send mail to
with "unsubscribe freebsd-ipfw" in the body of the message

Want to link to this message? Use this URL: <>