Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 3 Nov 2004 18:45:59 +0100
From:      Max Laier <max@love2party.net>
To:        freebsd-pf@freebsd.org
Subject:   Re: rdr to another machine and back
Message-ID:  <200411031846.06586.max@love2party.net>
In-Reply-To: <20041027135721.C553C68004@gunfright.epcdirect.co.uk>
References:  <20041027135721.C553C68004@gunfright.epcdirect.co.uk>

next in thread | previous in thread | raw e-mail | index | archive | help
--nextPart1135509.dVTT0hNEej
Content-Type: text/plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Hi Lawrence,

On Wednesday 27 October 2004 15:57, Lawrence Farr wrote:
> I'm trying to work out how to get a gateway machine
> to send all http requests to a separate machine and
> get them back, network looks like this:

[ hmm ... ASCII art killed by mail reader ]

Setup understood.

> So the router has 3 interfaces, one to the outside
> world, one externally available network and one
> internal. The proxy has 2 interfaces one to internal
> and one externally available. I can redirect port 80
> to a proxy on the router without any issue, but want
> to send them to the separate proxy machine. Has anyone
> done this, or does anyone know of a howto?

Well, it would be helpful to see tcpdumps from the proxy on the NIC connect=
ed=20
with the gateway. Also if you ask questions like this, please try to includ=
e=20
significant details about your ruleset. It's always helpful to check if the=
=20
rules that you tried are matched at all (pfctl -vsr or -vsn in your case).

Other than that, I don't know of a howto for this specific problem, the=20
pf.conf(5) manpage has some examples that redirect incoming SSH traffic to =
a=20
different host, though. It should be possible to take it from there. Make=20
sure that the proxy knows how to get back (i.e. has a route to the client -=
=20
remember "rdr" will not translate the source address!)

> Many thanks

[ Sorry for the delay, EuroBSDCon has been demanding - and a lot of FUN! ]

=2D-=20
/"\  Best regards,                      | mlaier@freebsd.org
\ /  Max Laier                          | ICQ #67774661
 X   http://pf4freebsd.love2party.net/  | mlaier@EFnet
/ \  ASCII Ribbon Campaign              | Against HTML Mail and News

--nextPart1135509.dVTT0hNEej
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (FreeBSD)

iD8DBQBBiRleXyyEoT62BG0RApfvAJ4/u8e10oItQA5WEsXV0y7ONPJH+wCcCOXv
lL5AczIL4hj4sOSj7+irHXg=
=QXYi
-----END PGP SIGNATURE-----

--nextPart1135509.dVTT0hNEej--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200411031846.06586.max>