From owner-freebsd-questions@FreeBSD.ORG Sun Jan 7 04:00:51 2007 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 17B4616A416 for ; Sun, 7 Jan 2007 04:00:49 +0000 (UTC) (envelope-from msoulier@gmail.com) Received: from nf-out-0910.google.com (nf-out-0910.google.com [64.233.182.188]) by mx1.freebsd.org (Postfix) with ESMTP id A886413C45B for ; Sun, 7 Jan 2007 04:00:48 +0000 (UTC) (envelope-from msoulier@gmail.com) Received: by nf-out-0910.google.com with SMTP id x37so8377764nfc for ; Sat, 06 Jan 2007 20:00:47 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:sender:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition:x-google-sender-auth; b=q3rs7RZ+rgKS/MDYTtVCluKDPAQJaN+40vnk0xqxzlXfr+wzQeTt430DJd9CXnT+JPxyeqBvFCQMAV3x5dWvCqOjhAzWR6nMqzpTpa/xYMJBitJHNO5wPYqvUF61XAQMfV5ZfCoGbpRFfMyzB7MvdZb4WHahhnHMjjxy7c9r+p4= Received: by 10.82.107.15 with SMTP id f15mr2466451buc.1168142447409; Sat, 06 Jan 2007 20:00:47 -0800 (PST) Received: by 10.82.170.18 with HTTP; Sat, 6 Jan 2007 20:00:47 -0800 (PST) Message-ID: Date: Sat, 6 Jan 2007 23:00:47 -0500 From: "Michael P. Soulier" Sender: msoulier@gmail.com To: "FreeBSD Questions" MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline X-Google-Sender-Auth: fd801f793724ec4f Subject: debugging ipnat X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 07 Jan 2007 04:00:51 -0000 I have a simple port-forwarding rule that I want to work from my gateway to a box on my LAN, but it doesn't seem to be working. [msoulier@kanga ~]$ sudo ipnat -l Password: List of active MAP/Redirect filters: rdr tun0 0.0.0.0/32 port 6882 -> 192.168.1.3 port 6882 tcp Trying to telnet to port 6882 on the public interface from outside, I just get a connection refused. The port is open in the firewall. tcpdump shows the traffic arriving, and a reset packet in response. tcpdump on the private interface shows nothing, so no attempt to forward the traffic is made. What am I doing wrong? Thanks, Mike -- Michael P. Soulier "Any intelligent fool can make things bigger and more complex... It takes a touch of genius - and a lot of courage to move in the opposite direction." --Albert Einstein