From owner-freebsd-questions@FreeBSD.ORG Wed May 4 17:28:36 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E827016A4CE for ; Wed, 4 May 2005 17:28:36 +0000 (GMT) Received: from lv.raad.tartu.ee (lv.raad.tartu.ee [194.126.106.110]) by mx1.FreeBSD.org (Postfix) with ESMTP id CBD9D43D31 for ; Wed, 4 May 2005 17:28:35 +0000 (GMT) (envelope-from toomas.aas@raad.tartu.ee) Received: Message by Barricade lv.raad.tartu.ee with ESMTP id j44HS6JM004505; Wed, 4 May 2005 20:28:06 +0300 Received: from INFO/SpoolDir by raad.tartu.ee (Mercury 1.48); 4 May 05 20:28:08 +0300 Received: from SpoolDir by INFO (Mercury 1.48); 4 May 05 20:27:45 +0300 Received: from [192.168.1.2] (192.168.1.2) by raad.tartu.ee (Mercury 1.48) with ESMTP; 4 May 05 20:27:45 +0300 Message-ID: <42790613.2070809@raad.tartu.ee> Date: Wed, 04 May 2005 20:27:47 +0300 From: Toomas Aas User-Agent: Mozilla Thunderbird 1.0RC1 (Windows/20041201) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Calvin Lane References: <995be75e05050409591da23458@mail.gmail.com> In-Reply-To: <995be75e05050409591da23458@mail.gmail.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable cc: questions@freebsd.org Subject: Re: Allowing GRE in IPFILTER X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 04 May 2005 17:28:37 -0000 Calvin Lane wrote: > Please let me know what the correct syntax is for allowing gre traffic = > through through an ipfilter firewall running BSD 4.10. Thanks. FreeBSD 4.10 contains IPFilter 3.4.31. For what you need to do, you need = PPTP proxy which is available only in IPFilter 4.1. So you'd need to install the latest IPFilter (4.1.8 I think) and then=20 just add this to ipnat.rules: map -> 0/32 proxy port 1723 pptp/tcp --=20 Toomas Aas -------------------------------------------------------- |arvutiv=F5rgu peaspetsialist | head specialist on computer networks| |Tartu Linnakantselei | Tartu City Office | ----------------------------------------------------- +372 736 1274