Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 23 Nov 1998 19:55:04 -0500
From:      Forrest Aldrich <forrie@navinet.net>
To:        freebsd-questions@FreeBSD.ORG
Subject:   Natd hell
Message-ID:  <19981123195504.A5012@navinet.net>

next in thread | raw e-mail | index | archive | help
If I put the rules:

	$fwcmd add divert natd all from any to any via xl0
	$fwcmd add 65000 pass all from any to any

I'm able to get out to the net from my internal net (10.0.0.0).
Otherwise, it doesn't work, regardless of whether I place 
an explicit allow for 10.0.0.0 to everywhere.

The internal network interface is 10.0.0.1 (xl1), the external
is my ISP address (xl0).

It seems to me now that this is an ipfw ACL issue.

If someone could mail me an example rc.firewall config that
implements natd with packet filters using an RFC net and
2 interfaces, I would appreciate it.   There is next to NO
information about this out there.  And the number of emails
I've received privately indicate there is certainly a need.
The manpage doesn't go into much detail.


Thanks....


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19981123195504.A5012>