Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 25 May 2000 11:26:25 -0400 (EDT)
From:      Brian Hechinger <wonko@users.tmok.com>
To:        freebsd-net@freebsd.org, freebsd-ipfw@freebsd.org
Subject:   question about natd/ipfw
Message-ID:  <200005251526.LAA59553@entropy.tmok.com>

next in thread | raw e-mail | index | archive | help
NOTE: sorry for the cross-post, tell me which list is more appropriate and i'll
      drop the other one.

a freebsd user has been helping me with this, but this is out of his realm of
experience.  i am setting up a NAT box/router for my Covad/DCA Net DSL link.

i will have two sets of outside IP addresses, a single IP address that will be
bound to my outside interface which comes from covad, and a /29 block from
DCA Net.  the /29 will be routed through the outside interface into the NAT
box, and from there i want to be able to use them as an "outside NAT pool"
externally they will just look like an average domain, but that i will be able
to redirect as i please internally.

so, my question is: what do i do with the /29?  do i create aliases on my 
outside interface for them all?  do i create aliases on my inside interface 
for them all?  do i bind them to lo0? attatching them to the outside interface
seems wrong to me as well as attatching them to the inside interface since
they should be listened to on either interface, hence my thought to bind them
to the loopback device since i view these things as being "virtual"

ipfw: using NAT and firewall_type="open" NAT blocks all non-redirected traffic?


thanks,

-brian


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ipfw" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200005251526.LAA59553>