From owner-freebsd-pf@FreeBSD.ORG Sat Jul 15 19:58:23 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 34B0516A4DF for ; Sat, 15 Jul 2006 19:58:23 +0000 (UTC) (envelope-from christian@qunec.net) Received: from spamvir03.de.clara.net (spamvir03.de.clara.net [212.82.240.102]) by mx1.FreeBSD.org (Postfix) with ESMTP id B373E43D70 for ; Sat, 15 Jul 2006 19:58:14 +0000 (GMT) (envelope-from christian@qunec.net) Received: from localhost ([127.0.0.1]) by spamvir03.de.clara.net with esmtp (Exim 4.62) (envelope-from ) id 1G1qHF-0002vn-FO; Sat, 15 Jul 2006 21:58:13 +0200 Received: from [192.168.0.221] (helo=[62.24.31.231]) by spamvir03.de.clara.net with esmtp (Exim 4.62) (envelope-from ) id 1G1qHF-0002vh-6t; Sat, 15 Jul 2006 21:58:13 +0200 Message-ID: <44B948CD.2060003@qunec.net> Date: Sat, 15 Jul 2006 21:58:05 +0200 From: christian User-Agent: Mozilla Thunderbird 1.0.8 (Windows/20060417) X-Accept-Language: en-us, en MIME-Version: 1.0 To: "Travis H." , freebsd-pf@freebsd.org References: <44B8F827.5000602@de.clara.net> <44B9398C.2080307@de.clara.net> In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: Subject: Re: RDR for locally generated traffic X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 15 Jul 2006 19:58:23 -0000 > Hmm, gosh, I don't really know without trying. I think so, it should > be like any other incoming packet as it arrives on the lo0 interface. > Try it and let us know! > > You could also use route-to, or a static route, rather than an if > alias, to get it to go to lo0, I think. So, didnt worked on lo0 (dont know why). Instead I used a secondary NIC which is not in use and assigned there the IP address, this worked of course, but isnt the nicest solution. This setup affects 10 servers, all of them will get this RDR rule and the secondary IP address. Maybe its the only way. cheers, Christian