From owner-freebsd-current@freebsd.org Mon Nov 2 23:44:27 2015 Return-Path: Delivered-To: freebsd-current@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C3059A25474 for ; Mon, 2 Nov 2015 23:44:27 +0000 (UTC) (envelope-from kp@FreeBSD.org) Received: from venus.codepro.be (venus.codepro.be [IPv6:2a01:4f8:162:1127::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "*.codepro.be", Issuer "Gandi Standard SSL CA 2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 8B66F1625 for ; Mon, 2 Nov 2015 23:44:27 +0000 (UTC) (envelope-from kp@FreeBSD.org) Received: from [IPv6:2a02:1811:2419:4e02:a528:e68b:dc0a:bd8c] (unknown [IPv6:2a02:1811:2419:4e02:a528:e68b:dc0a:bd8c]) by venus.codepro.be (Postfix) with ESMTPSA id 55CE91A165; Tue, 3 Nov 2015 00:44:21 +0100 (CET) Content-Type: text/plain; charset=utf-8 Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3106\)) Subject: Re: pf NAT and VNET Jails From: Kristof Provost In-Reply-To: <20151798.z4nmEG8eZc@hbsd-dev-laptop> Date: Tue, 3 Nov 2015 00:44:19 +0100 Cc: freebsd-current@freebsd.org Content-Transfer-Encoding: quoted-printable Message-Id: <089B842B-FE96-4016-BE6E-A63182422A9C@FreeBSD.org> References: <6607014.lfu2kQizLV@hbsd-dev-laptop> <20151798.z4nmEG8eZc@hbsd-dev-laptop> To: Shawn Webb X-Mailer: Apple Mail (2.3106) X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 02 Nov 2015 23:44:27 -0000 > On 02 Nov 2015, at 15:07, Shawn Webb = wrote: >=20 > On Monday, 02 November 2015 02:59:03 PM Kristof Provost wrote: >>=20 >> Can you add your pf.conf too? >>=20 >> I=E2=80=99ll try upgrading my machine to something beyond 290228 to = see if I can >> reproduce it. It=E2=80=99s on r289635 now, and seems to be fine. My = VNET jails >> certainly get their traffic NATed. >=20 > Sorry about that! I should've included it. It's pasted here: = http://ix.io/lLI >=20 > It's probably not the most concise. This is a laptop that can have one = of=20 > three interfaces online: re0 (ethernet on the laptop), wlan0 (you can = guess=20 > what that is), or ue0 (usb tethering from my phone). I used to be able = to=20 > specify NATing like that and pf would automatically figure out which = outgoing=20 > device to use. Seems like that's broken now. >=20 I=E2=80=99ve updated my machine and things still seem to be working. As you said, it=E2=80=99s probably related to the multiple nat entries. I=E2=80=99ll have to make a test setup, which=E2=80=99ll take a bit of = time, especially=20 since I=E2=80=99m messing with the host machine at the moment. Regards, Kristof