Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 01 Apr 2003 22:53:32 -0500
From:      Brian McCann <bjm1287@ritvax.isc.rit.edu>
To:        freebsd-questions@freebsd.org
Subject:   NATD & IPFW
Message-ID:  <000001c2f8cb$6e4f5e60$2f811581@garfield>

next in thread | raw e-mail | index | archive | help
Hi all.  I'm having an issue with security while trying to get natd to
work with ipfw.  I got my ipfw rules working great, so I added the natd
line in:

  ipfw add divert 8668 all from any to any via $EXTERNAL_INTERFACE

But I can't do anything (ping, fetch, etc) until I add:
  ipfw add pass all from any to any

Now, I may be wrong, but doesn't this pretty much open the box up?  I
tried changing the first "any" to my internal network, but that didn't
work, and I know I've got to be missing something.

If anyone would like to help me off-list, I could send you a copy of my
rule set if you'd like.

Thanks in advance,
--Brian




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?000001c2f8cb$6e4f5e60$2f811581>