Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 6 Jul 2000 20:10:19 -0400 (EDT)
From:      Chris Hill <chris@monochrome.org>
To:        Jens Sauer <pirol9999@gmx.net>
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   Re: IPFW-question
Message-ID:  <Pine.BSF.3.96.1000706195853.3807G-100000@localhost>
In-Reply-To: <20000706235327.C80FB37BA3B@hub.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 7 Jul 2000, Jens Sauer wrote:

> i am using ipfw for the very first time and have the following problem:
> 
> i configured my kernel with FIREWALL- and IPDIVERT-support fot NATD, 
> because of my private-address-clients.
>
>my rc.conf looks that way:

[snip] 

You don't mention your

firewall_type="SOMETHING"  # Firewall type (see /etc/rc.firewall) 

line; can we assume it's set to "simple"?

> my isdn-interface ISP0 is working fine, when i ping the internet from
> the firewall, it dials, all ok.
> 
> but when i traceroute into the internet from a LAN-client (192.168.0.x),
> the isdn-card on the firewall is successfully dialing (interface is up),
> but the packets are only going up to the network-card on the firewall,
> then i get a timeout.

[snip] 

I had a very similar problem, and was tearing my hair out for a long
time over it. It turns out that the "simple" firewall setup assumes that
you have real IP addresses on the _inside_, but you and I are running
RFC1918 nets on the inside. What you need to do is edit
/etc/rc.firewall.  Comment out the lines

    $fwcmd add deny all from 192.168.0.0:255.255.0.0 to any via ${oif}
    $fwcmd add deny all from any to 192.168.0.0:255.255.0.0 via ${oif}

Then, as root, type 'shutdown now' (without quotes), then return when it
asks you for a shell, then at the # prompt you can either hit Ctrl-D or
type 'exit' (without the quotes). This may not be the correct way to do
it, but it did the trick for me. 

> Please help a bloody newbie  :-)

Hope it was of some use.


--
Chris Hill               chris@monochrome.org
[1]    Bus error                     netscape




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.96.1000706195853.3807G-100000>