Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 30 Sep 2005 09:35:21 +0200
From:      Marcin Jessa <lists@yazzy.org>
To:        Ganbold <ganbold@micom.mng.net>
Cc:        freebsd-net@freebsd.org
Subject:   Re: ipfw bridge + fwd questions
Message-ID:  <20050930093521.5a17affd.lists@yazzy.org>
In-Reply-To: <6.2.1.2.2.20050930151357.03480eb0@202.179.0.80>
References:  <6.2.1.2.2.20050930151357.03480eb0@202.179.0.80>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 30 Sep 2005 15:39:49 +0900
Ganbold <ganbold@micom.mng.net> wrote:

> Hi,
> 
> I have a question regarding ipfw fwd rule.
> I'm using FreeBSD 5.4-STABLE and running on it bridging firewall
> using ipfw.
> 
> Now my question comes:)
> Can I use ipfw fwd rules against traffic coming to one of the bridged 
> interfaces?
Yes you can.
sysctl net.link.ether.bridge_ipfw=1 just like in your sysctl variables.

> I would like to forward some packets (which are destined to port
> 110)
> to some other router through third vr0 interface.
Use a divert rule for that.

In this example we send all the port 80 traffic to port 8000:
# ipfw add 1000 divert 8000 tcp from any to any 80
Read this article for more info:
http://freebsd.rogness.net/snort_inline/

Cheers
Marcin.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20050930093521.5a17affd.lists>