Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 5 Jan 2001 18:53:58 -0700 (MST)
From:      Nick Rogness <nick@rapidnet.com>
To:        Sean <devotwo@home.com>
Cc:        freebsd-net@freebsd.org
Subject:   Re: Problem with Multihomed Machine
Message-ID:  <Pine.BSF.4.21.0101051849530.24849-100000@rapidnet.com>
In-Reply-To: <3A567289.DBD37F7@home.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 5 Jan 2001, Sean wrote:

> >
> >         Is gateway_enable turned on ?  Is firewalling turned on?  If
> >         so, what do your rules look like?  Is natd enabled?
> 
> In /etc/rc.conf I have gateway_enable="YES" and natd_enable="YES".  For
> the firewalling,  I recompiled the kernel with the following options:
> 
> options IPFIREWALL
> options IPFIREWALL_VERBOSE
> options IPFIREWALL_VERBOSE_LIMIT=10
> options IPFIREWALL_FORWARD
> options IPFIREWALL_DEFAULT_TO_ACCEPT
> options IPDIVERT
> 
> from "ipfw list", I have the following rules in place
> 00100 divert 8668 ip from any to any via rl0
> 00100 allow ip from any to any via lo0
> 00200 deny ip from any to 127.0.0.0/8
> 65000 allow ip from any to any
> 65535 allow ip from any to any
> 
> I tried resetting the internal network card's IP address to 10.0.0.3,
> per another suggestion, but, that didn't have any effect.

> 
> In my natd configuration file, i have:
> 
> unregistered_only
> log yes
> use_sockets yes
> same_ports yes
> 

	What about the alias_address or interface option?  


> >

	Can you ping the inside interface on your FreeBSD machine from
	your Win2K box?  What does tcpdump show?  Change your firewall
	rule 65000 to "log" and look at the firewall logs.

Nick Rogness
- Drive defensively.  Buy a tank.




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-net" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0101051849530.24849-100000>