From owner-freebsd-questions@FreeBSD.ORG Fri Dec 26 06:45:54 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9D6C316A4CE for ; Fri, 26 Dec 2003 06:45:54 -0800 (PST) Received: from be-well.no-ip.com (lowellg.ne.client2.attbi.com [66.30.200.37]) by mx1.FreeBSD.org (Postfix) with ESMTP id 39B6843D41 for ; Fri, 26 Dec 2003 06:45:53 -0800 (PST) (envelope-from freebsd-questions-local@be-well.ilk.org) Received: by be-well.no-ip.com (Postfix, from userid 1147) id B137E66; Fri, 26 Dec 2003 09:45:52 -0500 (EST) Sender: lowell@be-well.ilk.org To: freebsd-questions@freebsd.org References: From: Lowell Gilbert Date: 26 Dec 2003 09:45:52 -0500 In-Reply-To: Message-ID: <44k74jr61r.fsf@be-well.ilk.org> Lines: 61 User-Agent: Gnus/5.09 (Gnus v5.9.0) Emacs/21.3 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii cc: Drew Robertson Subject: Re: A Challenge... NAT for PPP dial in user X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: freebsd-questions@freebsd.org List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Dec 2003 14:45:54 -0000 "Drew Robertson" writes: > I've been playing around with this for a while. > > I have a FreeBSD 4.8 box set as a gateway on my home LAN. I have 1 pc > downstairs, and a few dial up users... FreeBSD box has 2 network > cards, 1 for internal, 1 for external internet using cable & 1 56k > modem. > > Very simple problem... when a dial in user connects to the FreeBSD > gateway/router using PPP, NAT stops working on the PC downstairs and > won't work on the dial in PC either... > > I have complete LAN access (telnet, ssh, samba, ping etc) on both the > dial in PC and the downstairs PC, but somewhere my config is > preventing everyone from being able to access the internet at once. > > In rc.conf, I have my Gateway_enable=YES, defaultrouter=192.168.1.1, > router_enable=yes, proxyarp_all=yes... > > PPP.conf is simple... > > enable pap > enable passwdauth > set ifaddr 192.168.1.1 192.168.1.100-192.168.1.199 255.255.255.0 > add HISADDR 255.255.255.0 MYADDR > accept dns > set dns 203.2.75.132 > enable proxy > > In natd.conf > > interface tl0 > sameports yes > dynamic yes > > I'm running a firewall, but it is open for the TUN0 interface... > > I also have a divert natd (8668) allow all from any to any out via tl0 > > All other PC's on the LAN are windows clients... the one downstairs I > was able to just set a default gateway and it was up and running on > the internet, unfortunately it isn't done like that on a dial in setup > on windows... I can't use DHCP for the clients, as I'm not supposed > to have internet sharing running... > > Do I need to have an add statement in the PPP.conf, or do i have to > enable proxyall rather than enable proxy?? > > Worst thing about this is I can't find enough doco on it on the > net... I'll write my own when I get it done... I think that natd(8) and the NAT from ppp(8) are stepping on each other's toes. Try not enabling NAT in ppp(8) at all, and letting natd(8) take care of it. It's the same outside interface, after all; it should "just work". -- Lowell Gilbert, embedded/networking software engineer, Boston area: resume/CV at http://be-well.ilk.org:8088/~lowell/resume/ username/password "public"