From owner-freebsd-questions@FreeBSD.ORG Mon Jan 19 10:40:59 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9BB8D16A4CE for ; Mon, 19 Jan 2004 10:40:59 -0800 (PST) Received: from conn.mc.mpls.visi.com (conn.mc.mpls.visi.com [208.42.156.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id E1EBA43D58 for ; Mon, 19 Jan 2004 10:40:53 -0800 (PST) (envelope-from veldy@veldy.net) Received: from veldy.net (fuggle.veldy.net [209.98.200.33]) by conn.mc.mpls.visi.com (Postfix) with ESMTP id 7B7AA8878; Mon, 19 Jan 2004 12:40:53 -0600 (CST) Received: from localhost (localhost.veldy.net [127.0.0.1]) by veldy.net (Postfix) with ESMTP id 16BD91CC6A; Mon, 19 Jan 2004 12:40:53 -0600 (CST) Received: from veldy.net ([127.0.0.1]) by localhost (fuggle.veldy.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 27104-09; Mon, 19 Jan 2004 12:40:50 -0600 (CST) Received: from 4K3500B (localhost.veldy.net [127.0.0.1]) by veldy.net (Postfix) with SMTP id CD9CF1CC69; Mon, 19 Jan 2004 12:40:49 -0600 (CST) Message-ID: <006301c3debb$c2ef7730$d037630a@nic.target.com> From: "Thomas T. Veldhouse" To: , "freebsd-questions@FreeBSD. ORG" References: Date: Mon, 19 Jan 2004 12:40:48 -0600 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 X-Virus-Scanned: by amavisd-new at veldy.net Subject: Re: ipfw/nated stateful rules example X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Jan 2004 18:40:59 -0000 fbsd_user wrote: > Friends > In both 4.9 and 5.2 I can not get an rules set to function that only > uses keep-state' rules for outbound and inbound selection control > and the divert rule. > > Does anybody have an rules set they can share with me as an sample > for me to see. > > Thanks > The best sample is /etc/rc.firewall [and look in /usr/share/examples/ipfw for a potentially useful script to use while testing]. I have moved over to IPFILTER due to the fact that natd is userland based and is more problematic [than ipnat] because of it. Tom Veldhouse