From owner-freebsd-security Tue May 14 10:58:18 2002 Delivered-To: freebsd-security@freebsd.org Received: from exodus.ait.co.za (exodus.ait.co.za [66.8.26.2]) by hub.freebsd.org (Postfix) with SMTP id 1B62537B405 for ; Tue, 14 May 2002 10:58:12 -0700 (PDT) Received: from aragon [66.8.86.210] by exodus.ait.co.za (SMTPD32-4.06) id AE6A1560112; Tue, 14 May 2002 19:56:42 0200 Message-ID: <005501c1fb70$bb32ebb0$01000001@aragon> From: "Aragon Gouveia" To: "Miroslav Pendev" , References: <030301c1fb56$ef9fefc0$c801a8c0@vsivyoung> Subject: Re: ipfw + nat + port_redirect - works, but not for the internal net Date: Tue, 14 May 2002 19:56:52 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.50.4522.1200 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Howdy, Have you tried an ipfw fwd rule? Regards, Aragon ----- Original Message ----- From: "Miroslav Pendev" To: Sent: Tuesday, May 14, 2002 4:52 PM Subject: ipfw + nat + port_redirect - works, but not for the internal net > Hi Guys! > > I have FreeBSD 4.5 RELEASE as Firewall with two NICs: > > xl0 - external interface > xl1 - internal interface > > ipfw and natd + port_redirect works just fine! > > My problem is that when someone from the internal network > is trying to hit external_IP:redirected_port, the redirection > is not working for him - connection refused. > It works only for host from outside (Internet). > > For simplicity lets assume that the firewall type is *open*. > > What rules to ipfw or natd I need in order to permit > the port redirection to works for the internal hosts, also? > > I RTFM, I search the archives but I didn't found a clear > answer to that situation. > > This is common problem to the corporate servers behind > firewalls_with_natd_and_redirected_port and probably deserve > to be into FreeBSD handbook - otherwise, good documentation! > > There is some security concerns *is port_redirection a good idea > at all*, but that's it I need this working - don't ask why ;-) > > Thanks in advance! > > --Miro > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message