From owner-freebsd-questions@FreeBSD.ORG Fri Dec 26 14:05:59 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D72CA16A4CE for ; Fri, 26 Dec 2003 14:05:59 -0800 (PST) Received: from web40402.mail.yahoo.com (web40402.mail.yahoo.com [66.218.78.99]) by mx1.FreeBSD.org (Postfix) with SMTP id DA44843D46 for ; Fri, 26 Dec 2003 14:05:58 -0800 (PST) (envelope-from beantaxi@yahoo.com) Message-ID: <20031226220558.13042.qmail@web40402.mail.yahoo.com> Received: from [66.139.244.187] by web40402.mail.yahoo.com via HTTP; Fri, 26 Dec 2003 14:05:58 PST Date: Fri, 26 Dec 2003 14:05:58 -0800 (PST) From: The Bean To: Micheal Patterson , freebsd In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Subject: Re: natd.conf problem (was: natd problem (but close!) ) X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: beantaxi@yahoo.com List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Dec 2003 22:06:00 -0000 > Um. How many real IP's you have sitting on XL0? > > If it's only one, you don't to redirect_address on it otherwise, it will > lose internet access itself since all return traffic will go to the internal > address. If you have multiple IP's on xl0, redirect one of the aliased IP's > to the internal system. Otherwise, use redirect_port instead. I have 1 real IP sitting on xl0 on the gateway, and 1 real IP sitting on xl0 on the client (they both use xl0, coincidentally). The gateway's xl0 is configured for public IP xx.yy.zz.187 -- however, I'm doing redirect_address on xx.yy.zz.186, which isn't assigned to any interface. I suppose that's why my gateway could still access the Internet even though I had a redirect_address on. Hmmmm, I'm starting to feel like I've been misunderstanding how to use redirect_address . . . could it be that if I want to redirect a public IP to an interal host on my LAN, I must create an alias for that IP on the gateway's external interface? That would make sense -- otherwise, the NIC wouldn't know to use it. If so, where would I have read this? I'm not saying it's undocced; I'm sure it is, and so I'm wondering what I misread! Thanks Micheal -- I look forward to being educated. - T.B. > > -- > > Micheal Patterson > Network Administration > TSG Incorporated > 405-917-0600 > __________________________________ Do you Yahoo!? New Yahoo! Photos - easier uploading and sharing. http://photos.yahoo.com/