From owner-freebsd-questions@FreeBSD.ORG Fri Oct 21 12:54:05 2005 Return-Path: X-Original-To: questions@freebsd.org Delivered-To: freebsd-questions@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EC9EC16A41F for ; Fri, 21 Oct 2005 12:54:05 +0000 (GMT) (envelope-from freebsd-questions-local@be-well.ilk.org) Received: from mail26.sea5.speakeasy.net (mail26.sea5.speakeasy.net [69.17.117.28]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3A43543D45 for ; Fri, 21 Oct 2005 12:54:05 +0000 (GMT) (envelope-from freebsd-questions-local@be-well.ilk.org) Received: (qmail 28087 invoked from network); 21 Oct 2005 12:54:04 -0000 Received: from dsl092-078-145.bos1.dsl.speakeasy.net (HELO be-well.ilk.org) ([66.92.78.145]) (envelope-sender ) by mail26.sea5.speakeasy.net (qmail-ldap-1.03) with SMTP for ; 21 Oct 2005 12:54:04 -0000 Received: by be-well.ilk.org (Postfix, from userid 1147) id 084B234; Fri, 21 Oct 2005 08:54:03 -0400 (EDT) Sender: lowell@be-well.ilk.org To: "Efren Bravo" References: From: Lowell Gilbert Date: 21 Oct 2005 08:54:02 -0400 In-Reply-To: Message-ID: <441x2f3uad.fsf@be-well.ilk.org> Lines: 34 User-Agent: Gnus/5.09 (Gnus v5.9.0) Emacs/21.3 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: freeBSD Subject: Re: natd redirect help X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: freeBSD List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Oct 2005 12:54:06 -0000 "Efren Bravo" writes: > Hi, > > I've a freebsd5.4 with ipfw and natd. I need that external users can enter > to my internal network services (http, ftp, etc). > > freebsd box: > out interface: 200.x.x.x > in interface: 10.x.x.x > > /etc/rc.conf file: > ------------------ > gateway_enable="YES" > > firewall_enable="YES" > firewall_script="/etc/ipfw.rules" > firewall_logging="YES" > > natd_enable="YES" > natd_interface="vr0" > natd_flags="-f /etc/natd.conf" > > /etc/natd.conf file: > -------------------- > redirect_port tcp 10.x.x.x:8080 80 #redirec to internal web server > > > The question is if I've to open the port 80 on freeBSD's vr0 because I not > able to enter to those services. The packet will be checked again after it's been through natd, so you need an accept rule for it somewhere. But at that point, I guess it should be destined for port 8080 rather than 80.