From owner-freebsd-ipfw@FreeBSD.ORG Fri Jan 14 15:15:04 2011 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 202C1106564A for ; Fri, 14 Jan 2011 15:15:04 +0000 (UTC) (envelope-from drinking.coffee@gmail.com) Received: from c3p0.reverse.net (smtp-1.out.reverse.net [69.162.163.8]) by mx1.freebsd.org (Postfix) with ESMTP id EBD8D8FC14 for ; Fri, 14 Jan 2011 15:15:03 +0000 (UTC) Received: from [192.168.2.175] (localhost.reverse.net [127.0.0.1]) by c3p0.reverse.net (Postfix) with ESMTP id 8C0601D7800 for ; Fri, 14 Jan 2011 08:55:27 -0600 (CST) Message-ID: <4D3063DF.9060001@gmail.com> Date: Fri, 14 Jan 2011 08:55:27 -0600 From: Matthew Walker User-Agent: Thunderbird 2.0.0.24 (Windows/20100228) MIME-Version: 1.0 To: freebsd-ipfw@freebsd.org References: <4D2B625B.1030403@experts-exchange.com> In-Reply-To: <4D2B625B.1030403@experts-exchange.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: Fwd: stunnel transparent proxy X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 14 Jan 2011 15:15:04 -0000 Perhaps you should ask one of your readers. Isn't that what 'experts-exchange.com' is for? Why should we help you? Jay Corrales wrote: > From: Jay Corrales > Folks, > > In brief, I am trying to determine if this is possible with ipfw > rules. Please see below. > > Thank you. > > -------- Original Message -------- > Date: Fri, 7 Jan 2011 11:45:14 -0800 > To: freebsd-hackers@freebsd.org > Cc: freebsd-stable@freebsd.org, freebsd-ports@freebsd.org > Subject: stunnel transparent proxy > > Folks, > > Would it be possible to devise an ipfw 'fwd' rule to pass along a socket > connection with IP_BINDANY set via stunnel that forwards it to another > process? The problem I'm having is the vnc service on the other side > cannot reply back to the IP address because the routing does not redirect >