From owner-freebsd-ipfw Tue Jul 30 2:41:43 2002 Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 42BCD37B400 for ; Tue, 30 Jul 2002 02:41:42 -0700 (PDT) Received: from xy.blank.spb.ru (xy.blank.spb.ru [194.67.6.187]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2A65043E42 for ; Tue, 30 Jul 2002 02:41:41 -0700 (PDT) (envelope-from borman@blank.spb.ru) Received: from xy.blank.spb.ru (localhost.blank.spb.ru [127.0.0.1]) by xy.blank.spb.ru (8.12.5/8.12.5/blank) with ESMTP id g6U9fdTi001738 for ; Tue, 30 Jul 2002 13:41:39 +0400 (MSD) (envelope-from borman@xy.blank.spb.ru) Received: (from borman@localhost) by xy.blank.spb.ru (8.12.5/8.12.5/Submit) id g6U9fd0K001737 for freebsd-ipfw@FreeBSD.ORG; Tue, 30 Jul 2002 13:41:39 +0400 (MSD) Date: Tue, 30 Jul 2002 13:41:39 +0400 From: boris karlov To: freebsd-ipfw@FreeBSD.ORG Subject: Re: 4.6-RELEASE / NATD + IPFW + keep-state Message-ID: <20020730094139.GA1606@xy.blank.spb.ru> Mail-Followup-To: freebsd-ipfw@FreeBSD.ORG References: <20020729144758.A11849@rfc-networks.ie> <20020730055722.GD89241@blossom.cjclark.org> Mime-Version: 1.0 Content-Type: text/plain; charset=koi8-r Content-Disposition: inline In-Reply-To: <20020730055722.GD89241@blossom.cjclark.org> User-Agent: Mutt/1.4i Sender: owner-freebsd-ipfw@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Mon, 29 Jul 2002 22:57:22 -0700, "Crist J. Clark" wrote: > On Mon, Jul 29, 2002 at 02:47:58PM +0000, Philip Reynolds wrote: > > Hi, > > > > I'm having a few problems with using natd and ipfw. > > > > Originally, I was having serious serious problems trying to get > > stateful firewalling working with NAT. > > This is a FAQ, > > http://docs.freebsd.org/cgi/getmsg.cgi?fetch=13412+0+archive/2002/freebsd-net/20020217.freebsd-net > -- all the same it's a `twice processing' issue, AFAIU. suggestions: playing with in/out iface-specifiers and/or `skipto' for `divert'/`keep-state' rules. -- regards, boris karlov. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ipfw" in the body of the message