From owner-freebsd-net@FreeBSD.ORG Wed Jun 4 23:33:14 2008 Return-Path: Delivered-To: net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E7A681065671 for ; Wed, 4 Jun 2008 23:33:14 +0000 (UTC) (envelope-from arno@heho.snv.jussieu.fr) Received: from shiva.jussieu.fr (shiva.jussieu.fr [134.157.0.129]) by mx1.freebsd.org (Postfix) with ESMTP id 8DA1B8FC13 for ; Wed, 4 Jun 2008 23:33:14 +0000 (UTC) (envelope-from arno@heho.snv.jussieu.fr) Received: from heho.snv.jussieu.fr (heho.snv.jussieu.fr [134.157.184.22]) by shiva.jussieu.fr (8.14.2/jtpda-5.4) with ESMTP id m54NXCI8078565 ; Thu, 5 Jun 2008 01:33:13 +0200 (CEST) X-Ids: 164 Received: from heho.snv.jussieu.fr (localhost [127.0.0.1]) by heho.snv.jussieu.fr (8.13.3/jtpda-5.2) with ESMTP id m54NXBd7098594 ; Thu, 5 Jun 2008 01:33:11 +0200 (MEST) Received: (from arno@localhost) by heho.snv.jussieu.fr (8.13.3/8.13.1/Submit) id m54NX6ou098591; Thu, 5 Jun 2008 01:33:06 +0200 (MEST) (envelope-from arno) To: Petar Bogdanovic References: <20080604221738.GA6776@pintail.smokva.net> From: "Arno J. Klaassen" Date: 05 Jun 2008 01:33:05 +0200 In-Reply-To: <20080604221738.GA6776@pintail.smokva.net> Message-ID: Lines: 66 User-Agent: Gnus/5.09 (Gnus v5.9.0) Emacs/21.3 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-3.0 (shiva.jussieu.fr [134.157.0.164]); Thu, 05 Jun 2008 01:33:13 +0200 (CEST) X-Virus-Scanned: ClamAV 0.92/7366/Wed Jun 4 22:03:12 2008 on shiva.jussieu.fr X-Virus-Status: Clean X-Miltered: at jchkmail2.jussieu.fr with ID 48470A1A.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)! X-j-chkmail-Enveloppe: 48470A1A.000/134.157.184.22/heho.snv.jussieu.fr/heho.snv.jussieu.fr/ X-j-chkmail-Score: MSGID : 48470A1A.000 on jchkmail2.jussieu.fr : j-chkmail score : . : R=. U=. O=. B=0.009 -> S=0.009 X-j-chkmail-Status: Ham Cc: net@freebsd.org Subject: Re: IP-forwarding (help) X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 04 Jun 2008 23:33:15 -0000 Petar Bogdanovic writes: > On Wed, Jun 04, 2008 at 11:06:01PM +0200, Arno J. Klaassen wrote: > > > > Hello, > > > > this is probably a FAQ and/or I'm to tired, but I'd be pleased > > if anyone can tell me what I do wrong : > > > > I have a box with two interfaces, one connected to my lan > > (172.16. ), one to a test-box (192.168.1.1) : > > > > em0: flags=8843 metric 0 mtu 1500 > > options=9b > > ether xxx > > inet 172.16.1.240 netmask 0xffffff00 broadcast 172.16.1.255 > > media: Ethernet autoselect (1000baseTX ) > > status: active > > > > em1: flags=8843 metric 0 mtu 1500 > > options=9b > > ether xxx > > inet 192.168.1.254 netmask 0xffffff00 broadcast 192.168.1.255 > > media: Ethernet autoselect (1000baseTX ) > > status: active > > > > > > I enable ip.forwarding : > > > > # sysctl net.inet.ip.forwarding > > net.inet.ip.forwarding: 1 > > > > > > And this is my routing table : > > > > Internet: > > Destination Gateway Flags Refs Use Netif Expire > > default 172.16.1.254 UGS 0 20 em0 > > 127.0.0.1 127.0.0.1 UH 0 0 lo0 > > 172.16.1.0/24 link#3 UC 0 0 em0 > > 172.16.1.6 xxxxxxxxxxxxxxxxx UHLW 1 87 em0 1194 > > 172.16.1.230 xxxxxxxxxxxxxxxxx UHLW 1 286 em0 572 > > 172.16.1.240 xxxxxxxxxxxxxxxxx UHLW 1 0 lo0 > > 172.16.1.254 xxxxxxxxxxxxxxxxx UHLW 2 0 em0 487 > > 192.168.1.0/24 link#4 UC 0 0 em1 > > 192.168.1.1 xxxxxxxxxxxxxxxxx UHLW 1 2 em1 616 > > 192.168.1.254 xxxxxxxxxxxxxxxxx UHLW 1 0 lo0 > > > > For this I added to rc.conf : > > > > static_routes="test lan" > > route_test="-net 192.168.1.0/24 192.168.1.254" > > route_lan="-net 172.16.1.0/24 172.16.1.240" > > I'm pretty sure that you don't need these three lines. Turning > net.inet.ip.forwarding on should be enough. That's what I thought? Without the above lines it doesn't work either. And ip.forwarding "works" in the sense trafic goes from 192.168.1.254 forward to 172.16.1.240 over lo0, but then taking "link#3" to go to 172.16.1.0/24 fails. I feel this is /me still not fully understand routing tables. NB, this is on 7-stable-amd64 Arno