Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 08 Dec 2020 12:06:54 +0000
From:      bugzilla-noreply@freebsd.org
To:        bugs@FreeBSD.org
Subject:   [Bug 251683] ipnat not working properly rdr
Message-ID:  <bug-251683-227@https.bugs.freebsd.org/bugzilla/>

next in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D251683

            Bug ID: 251683
           Summary: ipnat not working properly rdr
           Product: Base System
           Version: 12.1-STABLE
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: bin
          Assignee: bugs@FreeBSD.org
          Reporter: Z462vasa@mail.lviv.ua

not working properly

FreeBSD 12.1-STABLE r362880 GENERIC  amd64


it doesn't work

ipnat_enable=3D"YES"
ipnat_rules=3D"/etc/ipnat.rules"

start
rc.local
/sbin/ipnat -CF -f /etc/ipnat.rules


ipnat.rules
rdr em0 123.123.123.123/32 port 3398   -> 192.168.3.241 port 3389
map em0 192.168.0.0/22  -> 123.123.123.123/32    portmap tcp/udp 33256:58999
map em0 192.168.0.0/22  -> 123.123.123.123/32



The recorder does not work for video (port 554).
I have to restart every day. /sbin/ipnat -CF -f /etc/ipnat.rules

ipnat -s
0       proxy create fail in
0       proxy fail in
0       bad nat in
0       bad nat new in
0       bad next addr in
0       bucket max in
0       clone nomem in
0       decap bad in
0       decap fail in
0       decap pullup in
0       divert dup in
0       divert exist in
0       drop in
0       exhausted in
0       icmp address in
0       icmp basic in
18446744073709550825    inuse in
0       icmp mbuf wrong size in
1268    icmp header unmatched in
0       icmp rebuild failures in
0       icmp short in
0       icmp packet size wrong in
0       IFP address fetch failures in
21329512        packets untranslated in
0       NAT insert failures in
281926  NAT lookup misses in
21293509        NAT lookup nowild in
0       new ifpaddr failed in
0       memory requests failed in
0       table max reached in
32543618        packets translated in
0       finalised failed in
0       search wraps in
0       null translations in
0       translation exists in
0       no memory in
23%     hash efficiency in
95.55%  bucket usage in
0       minimal length in
17      maximal length in
4.211   average length in
0       proxy create fail out
0       proxy fail out
0       bad nat out
0       bad nat new out
0       bad next addr out
0       bucket max out
0       clone nomem out
0       decap bad out
0       decap fail out
0       decap pullup out
0       divert dup out
0       divert exist out
0       drop out
0       exhausted out
0       icmp address out
0       icmp basic out
18446744073709551480    inuse out
0       icmp mbuf wrong size out
643     icmp header unmatched out
0       icmp rebuild failures out
0       icmp short out
0       icmp packet size wrong out
0       IFP address fetch failures out
33693917        packets untranslated out
0       NAT insert failures out
280104  NAT lookup misses out
33895897        NAT lookup nowild out
0       new ifpaddr failed out
0       memory requests failed out
0       table max reached out
20091118        packets translated out
0       finalised failed out
0       search wraps out
0       null translations out
0       translation exists out
0       no memory out
23%     hash efficiency out
95.31%  bucket usage out
0       minimal length out
15      maximal length out
4.235   average length out
0       log successes
0       log failures
2703    added in
239212  added out
6806    active
0       transparent adds
0       divert build
235109  expired
0       flush all
0       flush closing
0       flush queue
0       flush state
0       flush timeout
64949   hostmap new
0       hostmap fails
179290  hostmap add
0       hostmap NULL rule
0       log ok
0       log fail
0       orphan count
82      rule count
8       map rules
74      rdr rules
0       wilds


ipnat -lv

192.168.3.23,2.58.44.10 -> 123.123.123.123,0.0.0.0 (use =3D 8 hv =3D 104644=
3396)
192.168.1.14,18.205.40.43 -> 123.123.123.123,0.0.0.0 (use =3D 63 hv =3D 158=
2554020)
192.168.3.102,79.124.240.239 -> 123.123.123.123,0.0.0.0 (use =3D 4 hv =3D
3756521886)
192.168.3.21,52.114.148.9 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D 9929=
98888)
192.168.3.191,31.13.81.36 -> 123.123.123.123,0.0.0.0 (use =3D 3 hv =3D 2124=
897214)
192.168.3.46,3.123.248.34 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D 1576=
531846)
192.168.3.21,209.85.233.188 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
2077752226)
192.168.1.11,34.237.129.180 -> 123.123.123.123,0.0.0.0 (use =3D 5 hv =3D
2130959300)
192.168.3.183,54.93.254.235 -> 123.123.123.123,0.0.0.0 (use =3D 5 hv =3D
4294966252)
192.168.3.92,8.8.4.4 -> 123.123.123.123,0.0.0.0 (use =3D 24 hv =3D 30880116=
64)
192.168.3.124,204.94.91.139 -> 123.123.123.123,0.0.0.0 (use =3D 3 hv =3D
4273470872)
192.168.3.16,142.250.75.14 -> 123.123.123.123,0.0.0.0 (use =3D 4 hv =3D 101=
6591772)
192.168.3.124,162.247.242.21 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
4226285508)
192.168.3.102,64.233.165.188 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
4249867136)
192.168.3.52,8.8.8.8 -> 123.123.123.123,0.0.0.0 (use =3D 5 hv =3D 201479412=
8)
192.168.3.183,8.8.4.4 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D 18464976=
80)
192.168.3.102,64.233.164.188 -> 123.123.123.123,0.0.0.0 (use =3D 4 hv =3D
4249867136)
192.168.3.180,18.205.40.43 -> 123.123.123.123,0.0.0.0 (use =3D 9 hv =3D 211=
9687076)
192.168.1.11,3.123.248.34 -> 123.123.123.123,0.0.0.0 (use =3D 3 hv =3D 1475=
606406)
192.168.3.102,64.233.161.188 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
4249342848)
192.168.1.29,216.58.209.14 -> 123.123.123.123,0.0.0.0 (use =3D 4 hv =3D 106=
7677104)
192.168.1.29,8.8.8.8 -> 123.123.123.123,0.0.0.0 (use =3D 4 hv =3D 974344592)
192.168.3.29,162.84.148.67 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D 320=
7592388)
192.168.3.180,3.123.248.34 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D 184=
4967302)
192.168.3.196,54.93.254.235 -> 123.123.123.123,0.0.0.0 (use =3D 5 hv =3D
3758095340)
192.168.3.136,173.194.222.109 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
3686782426)
192.168.3.180,161.117.95.125 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
4206885826)
192.168.1.14,35.171.62.218 -> 123.123.123.123,0.0.0.0 (use =3D 49 hv =3D
3162462150)
192.168.3.20,173.194.79.189 -> 123.123.123.123,0.0.0.0 (use =3D 2 hv =3D
2057295322)
192.168.3.102,161.117.71.156 -> 123.123.123.123,0.0.0.0 (use =3D 3 hv =3D
4237294530)

the problem is still not trashed=20
(https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D240400)

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-251683-227>