From owner-freebsd-net@FreeBSD.ORG Thu Jul 14 05:31:37 2005 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AAC9F16A41C for ; Thu, 14 Jul 2005 05:31:37 +0000 (GMT) (envelope-from compunction@gmail.com) Received: from zproxy.gmail.com (zproxy.gmail.com [64.233.162.196]) by mx1.FreeBSD.org (Postfix) with ESMTP id 49DFB43D46 for ; Thu, 14 Jul 2005 05:31:36 +0000 (GMT) (envelope-from compunction@gmail.com) Received: by zproxy.gmail.com with SMTP id i11so189837nzi for ; Wed, 13 Jul 2005 22:31:36 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=ZFgZ6vpgjV31t7IJDtp5zMcukXl87p49elqspXOLOU6v2gmXa4XWWcAbEPuwilS/gxWEIO6wICN8Q00h+7NP4Dnmw0DVoixQS79sbhfIbXvlip+LxNC0F6uxnQNe2HuHIhf5LyQyNAQQcGGLxY0Jc0cDImSygNEAf9WeUT1txlI= Received: by 10.36.36.14 with SMTP id j14mr64679nzj; Wed, 13 Jul 2005 22:31:36 -0700 (PDT) Received: by 10.36.39.18 with HTTP; Wed, 13 Jul 2005 22:31:36 -0700 (PDT) Message-ID: <9f9a8c4005071322311907b4b@mail.gmail.com> Date: Thu, 14 Jul 2005 01:31:36 -0400 From: compunction To: Alex Povolotsky In-Reply-To: <42D536EC.5030500@webmail.sub.ru> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <42D536EC.5030500@webmail.sub.ru> Cc: freebsd-net@freebsd.org Subject: Re: GRE and PF problem X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: compunction List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 14 Jul 2005 05:31:37 -0000 GRE needs to pass bidirectional. You will need a binat to make it work. I have not found a firewall that will allow GRE to work with a many to one nat. -Mark On 7/13/05, Alex Povolotsky wrote: > Hello! >=20 > I'm using FreeBSD (5.3-RELEASE-p5) as internet access server, and I have > to NAT GRE packets. I'm using pf. >=20 > The problem is that SOMETIMES PF fails to create proper rule using nat, > while binat works fine. >=20 > Not only I do not want to expose Windows boxes (even if those addresses > are firewalled), but it's also a terrible waste of real IPs. >=20 > Can anyone point me if I have incorrect PF config, or PF just work > poorly with gre? >=20 > Alex. >=20 >=20 > _______________________________________________ > freebsd-net@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-net > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" >