From owner-freebsd-questions Thu Jan 29 15:57:59 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id PAA20812 for questions-outgoing; Thu, 29 Jan 1998 15:57:59 -0800 (PST) (envelope-from owner-freebsd-questions@FreeBSD.ORG) Received: from awfulhak.org (awfulhak.demon.co.uk [158.152.17.1]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id PAA20530 for ; Thu, 29 Jan 1998 15:57:36 -0800 (PST) (envelope-from brian@Awfulhak.org) Received: from gate.lan.awfulhak.org (localhost [127.0.0.1]) by awfulhak.org (8.8.7/8.8.7) with ESMTP id WAA23597; Thu, 29 Jan 1998 22:16:00 GMT (envelope-from brian@gate.lan.awfulhak.org) Message-Id: <199801292216.WAA23597@awfulhak.org> X-Mailer: exmh version 2.0.1 12/23/97 To: Christoph Kukulies cc: Brian Somers , freebsd-questions@FreeBSD.ORG, chrisa@commlet.com Subject: Re: natd/libalias question In-reply-to: Your message of "Thu, 29 Jan 1998 08:38:48 GMT." <19980129083848.27473@gil.physik.rwth-aachen.de> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Thu, 29 Jan 1998 22:16:00 +0000 From: Brian Somers Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG X-To-Unsubscribe: mail to majordomo@FreeBSD.org "unsubscribe questions" > On Wed, Jan 28, 1998 at 08:39:00PM +0000, Brian Somers wrote: > > [.....] > > > It works! > > > > > > With the following /etc/rc.firewall: > > > > > > /sbin/ipfw -f flush > > > /sbin/ipfw add divert natd all from any to any via le0 > > > /sbin/ipfw add divert natd all from any to any via ipi0 > > > /sbin/ipfw add pass all from any to any > > > > > > And the following natd start line: > > > > > > natd -redirect_address 192.168.1.114 0.0.0.0 -n ipi0 > > > > > > I still have to understand why this natd line makes it work for any > > > host on my local network, though :-) > > > > I'm surprised the first line doesn't break things :-| It's not > > necessary and shouldn't really be there. > > You mean the second line, don't you? : > > "/sbin/ipfw add divert natd all from any to any via le0" You need to divert stuff on the same interface (the external one) as natd is running on. [.....] > -- > --Chris Christoph P. U. Kukulies kuku@gil.physik.rwth-aachen.de -- Brian , , Don't _EVER_ lose your sense of humour....