Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Jan 1997 16:48:08 +1100 (EDT)
From:      Darren Reed <avalon@coombs.anu.edu.au>
To:        brian@awfulhak.demon.co.uk (Brian Somers)
Cc:        chris@mail.bb.cc.wa.us, hackers@freebsd.org
Subject:   Re: IPFILTER
Message-ID:  <199701130549.VAA20725@freefall.freebsd.org>
In-Reply-To: <199701122304.XAA08535@awfulhak.demon.co.uk> from "Brian Somers" at Jan 12, 97 11:04:02 pm

next in thread | previous in thread | raw e-mail | index | archive | help
In some mail from Brian Somers, sie said:
> 
> > Im setting up ipfilter to work on my system and I have it installed. 
> > But i need help configuring the rules so that it will actually work.
> > 
> > 
> > I have two cards in the FBSD box.  fxp0 and vx0
> > fpx0 is 208.8.136.10
> > vx0 is 10.16.14.1
> > 
> > i have a client on 10.16.14.100 and i want it to be translated to
> > a 208.8.136.10 address so that it can go out.
> > 
> > how do i do this?
> > 
> > thanks
> > 
> > chris coleman
> 
> You need something like
> 
>     map tun0 10.16.14.0/24 -> 208.8.136.10
> 
> in /etc/natrules (say), then run 'ipnat /etc/natrules' or something like 
> that... I got this stuff working, but ftp DATA commands never worked and it 
> crashed the machine a few times.  Socks, cached and ppp -alias are all far 
> superior !

ftp should always be done with a proxy agent.

Darren



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199701130549.VAA20725>