From owner-freebsd-questions@FreeBSD.ORG Wed Mar 29 07:54:28 2006 Return-Path: X-Original-To: freebsd-questions@FreeBSD.ORG Delivered-To: freebsd-questions@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 885B416A400 for ; Wed, 29 Mar 2006 07:54:28 +0000 (UTC) (envelope-from norgaard@locolomo.org) Received: from strange.daemonsecurity.com (59.Red-81-33-11.staticIP.rima-tde.net [81.33.11.59]) by mx1.FreeBSD.org (Postfix) with ESMTP id 11CDD43D48 for ; Wed, 29 Mar 2006 07:54:28 +0000 (GMT) (envelope-from norgaard@locolomo.org) Received: from [172.24.8.84] (generic.atosorigin.es [212.170.156.200]) by strange.daemonsecurity.com (Postfix) with ESMTP id D60C72E04B; Wed, 29 Mar 2006 09:54:33 +0200 (CEST) Message-ID: <442A3D2D.4080701@locolomo.org> Date: Wed, 29 Mar 2006 09:54:21 +0200 From: Erik Norgaard User-Agent: Thunderbird 1.5 (X11/20060118) MIME-Version: 1.0 To: fbsd_user@a1poweruser.com References: In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Cc: "freebsd-questions@FreeBSD. ORG" Subject: Re: FBSD 6.0 ipfilter nat redirect not working. X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Mar 2006 07:54:28 -0000 fbsd_user wrote: > # /root >ipnat -l > List of active MAP/Redirect filters: > map rl0 10.0.10.0/29 -> 0.0.0.0/32 proxy port ftp ftp/tcp > map rl0 0.0.0.0/0 -> 0.0.0.0/32 proxy port ftp ftp/tcp > map rl0 10.0.10.0/29 -> 0.0.0.0/32 > rdr rl0 0.0.0.0/0 port 6188 -> 10.0.10.4 port 80 tcp > > List of active sessions: > RDR 10.0.10.4 80 <- -> 79.69.59.49 6188 [65.45.227.95 > 2698] > MAP 10.0.10.6 1857 <- -> 79.69.59.49 1857 > [216.155.193.144 5050] > > Nothing happens. No ipf.log records on gateway box and > no ipf.log records on the LAN web server box. > There is firewall rule to log & pass from any to 10.0.10.4 port = 80 > keep state > And any packet that does not match a firewall rule get logged and > dropped. Please post your filter ruleset also. Erik -- Ph: +34.666334818 web: www.locolomo.org S/MIME Certificate: www.daemonsecurity.com/ca/8D03551FFCE04F06.crt Subject ID: 9E:AA:18:E6:94:7A:91:44:0A:E4:DD:87:73:7F:4E:82:E7:08:9C:72 Fingerprint: 5B:D5:1E:3E:47:E7:EC:1C:4C:C8:3A:19:CC:AE:14:F5:DF:18:0F:B9