From owner-freebsd-questions@FreeBSD.ORG Wed Oct 15 07:31:51 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C791816A4B3 for ; Wed, 15 Oct 2003 07:31:51 -0700 (PDT) Received: from p1028-ipbffx02marunouchi.tokyo.ocn.ne.jp (p1028-ipbffx02marunouchi.tokyo.ocn.ne.jp [220.111.132.28]) by mx1.FreeBSD.org (Postfix) with ESMTP id 41F9743F75 for ; Wed, 15 Oct 2003 07:31:48 -0700 (PDT) (envelope-from lukek@meibin.net) Received: (qmail 27797 invoked by uid 89); 15 Oct 2003 14:31:47 -0000 Received: from unknown (HELO ?127.0.0.1?) (192.168.10.35) by 192.168.20.5 with SMTP; 15 Oct 2003 14:31:47 -0000 Date: Wed, 15 Oct 2003 23:25:12 +0900 From: Luke Kearney To: freebsd-questions@freebsd.org In-Reply-To: <24540000.1066226966@lerlaptop-red.iadfw.net> References: <44oewiha2w.fsf@be-well.ilk.org> <24540000.1066226966@lerlaptop-red.iadfw.net> Message-Id: <20031015232128.08C5.LUKEK@meibin.net> MIME-Version: 1.0 Content-Type: text/plain; charset="ISO-2022-JP" Content-Transfer-Encoding: 7bit X-Mailer: Becky! ver. 2.07.01 Subject: Re: IPNAT/Slow TCP/Pings fine/4.8-REL (fwd) X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Oct 2003 14:31:51 -0000 On Wed, 15 Oct 2003 09:09:26 -0500 Larry Rosenman granted us these pearls of wisdom: > > > --On Wednesday, October 15, 2003 10:03:35 -0400 Lowell Gilbert > wrote: > > > Larry Rosenman writes: > > > >> I was trying(!) to help a friend out, and built a 4.8-REL box > >> to play Router/NAT and it's ALMOST working. I can't seem to telnet/surf > >> from NAT'd addresses, but PING works fine. > > > > You can ping to the same addresses that you can't telnet to? > > On inside machines? > yes. I.E. from 192.168.30.53 I can ping 207.158.72.11, and telnet > to 207.158.72.11. While that telnet is up, I can log on to the FreeBSD > box, see the translation in ipnat -l, telnet to 207.158.72.11, and see the > session in 207.158.72.11's netstat, but I can't do anything useful on the > session from the 192.168.30.53 box. > > LER G'Day, What are the firewall rules like ? Has IPFilter been set to pass all ? ( or ipfw in case your using that instead )? Do you get name resolution if you query an external server via nslookup ? Just for kicks try enabling ipfilter with a ruleset like "" pass in log from any to any "" HTH LukeK