Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 1 Dec 2001 16:41:55 -0800
From:      "Crist J . Clark" <cristjc@earthlink.net>
To:        Nick Rogness <nick@rogness.net>
Cc:        Sheldon Hearn <sheldonh@starjuice.net>, freebsd-questions@FreeBSD.ORG
Subject:   Re: Diagrams on natd?
Message-ID:  <20011201164155.L13613@blossom.cjclark.org>
In-Reply-To: <Pine.BSF.4.21.0112011816310.48587-100000@cody.jharris.com>; from nick@rogness.net on Sat, Dec 01, 2001 at 06:23:21PM -0600
References:  <20011201145441.H13613@blossom.cjclark.org> <Pine.BSF.4.21.0112011816310.48587-100000@cody.jharris.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, Dec 01, 2001 at 06:23:21PM -0600, Nick Rogness wrote:
> On Sat, 1 Dec 2001, Crist J . Clark wrote:
> 
> > On Wed, Nov 21, 2001 at 08:06:20PM +0200, Sheldon Hearn wrote:
> > > 
> > > 
> > > On Wed, 21 Nov 2001 11:17:26 CST, Nick Rogness wrote:
> > > 
> > > > 	I made an animated gif that steps through the nat process:
> > > > 
> > > > 	http://freebsd.rogness.net/redirect.cgi?basic/nat.html
> > > 
> > 
> 
> > As for the web page quoted above, it is a pretty good primer, but it
> > gives some bad advice in the last section. The example is how to block
> > incoming traffic on tcp/53. The example is bad for two reasons. First,
> > blocking tcp/53 breaks DNS. 
> 
> 	Only zone transfers.  Which is what the example was intended to
> 	do.

This is a common misconception. Blocking 53/tcp breaks queries too,
but you don't see the problems it creates too frequently.

> > Second, you are better off doing this
> > _before_ the divert(4) rule. You are better off _blocking_ packets
> > before the divert(4) rule whenever possible. That is,
> > 
> >   # ipfw add 40 deny tcp from any to 20.30.40.51 53 in via xl0
> 
> 	I agree, however,that is OK if you know what your public IP
> 	is.  In a natd-dynamic configuration.  This was written just prior
> 	to the release of the "me" flag in ipfw (I Believe).

OK,

  # ipfw add 40 deny tcp from any to any 53 in via xl0

Is fine too.
-- 
Crist J. Clark                     |     cjclark@alum.mit.edu
                                   |     cjclark@jhu.edu
http://people.freebsd.org/~cjc/    |     cjc@freebsd.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011201164155.L13613>