From owner-freebsd-net@FreeBSD.ORG Tue Apr 25 06:19:02 2006 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 05C1B16A404 for ; Tue, 25 Apr 2006 06:19:02 +0000 (UTC) (envelope-from helge.oldach@atosorigin.com) Received: from mizar.origin-it.net (mail.de.atosorigin.com [194.8.96.234]) by mx1.FreeBSD.org (Postfix) with ESMTP id 50DE443D46 for ; Tue, 25 Apr 2006 06:19:00 +0000 (GMT) (envelope-from helge.oldach@atosorigin.com) Received: from matar.hbg.de.int.atosorigin.com (dehsfw3e.origin-it.net [194.8.96.68]) by mizar.origin-it.net (8.13.6/8.13.6/hmo020206) with ESMTP id k3P6IwRB050842 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 25 Apr 2006 08:18:58 +0200 (CEST) (envelope-from helge.oldach@atosorigin.com) Received: from galaxy.hbg.de.ao-srv.com (galaxy.hbg.de.ao-srv.com [161.89.20.4]) by matar.hbg.de.int.atosorigin.com (8.13.6/8.13.6/hmo020206) with ESMTP id k3P6Iwj8085008; Tue, 25 Apr 2006 08:18:58 +0200 (CEST) (envelope-from helge.oldach@atosorigin.com) Received: (from hmo@localhost) by galaxy.hbg.de.ao-srv.com (8.9.3p2/8.9.3/hmo30mar03) id IAA00144; Tue, 25 Apr 2006 08:18:57 +0200 (MET DST) Message-Id: <200604250618.IAA00144@galaxy.hbg.de.ao-srv.com> In-Reply-To: <87k69f0ydi.fsf@lk107.tempest.sk> from Ludovit Koren at "Apr 24, 2006 5:47: 5 pm" To: lk@tempest.sk (Ludovit Koren) Date: Tue, 25 Apr 2006 08:18:56 +0200 (MET DST) From: Helge Oldach X-Address: Atos Origin GmbH, Friesenstraße 13, D-20097 Hamburg, Germany X-Phone: +49 40 7886 7464, Fax: +49 40 7886 9464, Mobile: +49 160 4782077 MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Cc: freebsd-net@freebsd.org Subject: Re: Routes for interface X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Apr 2006 06:19:02 -0000 Ludovit Koren: >is there any possibility to set the routing statically on a multi-homed >host so, that the packet is sent back via the same interface, as it has >came from? ipfw(4) is your friend, for example on a box with addresses 192.168.20.31 and 172.16.164.54 with respective gateways 192.168.21.254 and 172.16.164.1: 00100 31716 3368679 allow ip from 192.168.20.31 to 192.168.20.0/23 00200 671653 64044345 fwd 192.168.21.254 ip from 192.168.20.31 to any 00300 59889 3353166 allow ip from 172.16.164.54 to 172.16.164.0/22 00400 317 28628 fwd 172.16.164.1 ip from 172.16.164.54 to any 00500 7075682 948430737 allow ip from any to any 65535 0 0 deny ip from any to any Helge