From owner-freebsd-questions@freebsd.org Fri Apr 2 20:04:14 2021 Return-Path: Delivered-To: freebsd-questions@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 3DFA95B0533 for ; Fri, 2 Apr 2021 20:04:14 +0000 (UTC) (envelope-from 4250.82.1d4cf000118fc81.b4ab05ac2da87643a5165d6e07fa11dd@email-od.com) Received: from s1-b0c6.socketlabs.email-od.com (s1-b0c6.socketlabs.email-od.com [142.0.176.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4FBrbx11DTz3qYg for ; Fri, 2 Apr 2021 20:04:12 +0000 (UTC) (envelope-from 4250.82.1d4cf000118fc81.b4ab05ac2da87643a5165d6e07fa11dd@email-od.com) DKIM-Signature: v=1; a=rsa-sha256; d=email-od.com;i=@email-od.com;s=dkim; c=relaxed/relaxed; q=dns/txt; t=1617393853; x=1619985853; h=content-transfer-encoding:content-type:mime-version:references:in-reply-to:message-id:subject:to:from:date:x-thread-info; bh=ubo2QtROcnvRmQ808gWDRQvNVGnw3mc1vJx1ZKzchSM=; b=F+VlpTY5/2XhyOg6FScQs6h1rqTv+JYMpE3T9yiHqIzByRdHmwx2pb50IV7n0+sx0PgD3G6rTxVbMV0qwHyGv0+GCsgkJYG32Q850ImkJUkeYGxbJNQ31hpkruK25+ZJzLwR2jcdeKu65aJQUR8oqogCRVt87fS6Upt3FM4vGYU= X-Thread-Info: NDI1MC4xMi4xZDRjZjAwMDExOGZjODEuZnJlZWJzZC1xdWVzdGlvbnM9ZnJlZWJzZC5vcmc= Received: from r2.h.in.socketlabs.com (r2.h.in.socketlabs.com [142.0.180.12]) by mxsg2.email-od.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Fri, 2 Apr 2021 16:03:59 -0400 "MachineName": "HO-PR-REC02", "Ehlo": true, "HeloDomain": "smtp.lan.sohara.org", "Timestamp": "2021-04-02T16:03:58.8239103-04:00", "Auth": "CramMd5", "MessageNumber": 1, "RemoteIp": "185.202.17.215", "RemotePort": 0, "LocalIp": "10.28.180.12", "LocalPort": "2526", "MailFrom": { "Email": "steve@sohara.org", "Name": null, "Local": "steve", "Domain": "sohara.org" }, "TlsLogData": { "Enabled": true, "CertSubject": null, "CryptProtocol": 3072, "CryptCipherAlgId": 26128, "CryptHashAlgId": 32781, "CryptExchangeAlgId": 44550 } } Received: from smtp.lan.sohara.org (EMTPY [185.202.17.215]) by r2.h.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Fri, 2 Apr 2021 16:03:58 -0400 Received: from [192.168.63.1] (helo=steve.lan.sohara.org) by smtp.lan.sohara.org with smtp (Exim 4.94 (FreeBSD)) (envelope-from ) id 1lSQ1N-000Mbn-6T for freebsd-questions@freebsd.org; Fri, 02 Apr 2021 21:03:57 +0100 Date: Fri, 2 Apr 2021 21:03:56 +0100 From: Steve O'Hara-Smith To: freebsd-questions@freebsd.org Subject: Re: pf or ipfw for NAT Message-Id: <20210402210356.637a3ed714957fb9c5fdfa3a@sohara.org> In-Reply-To: <50dcf18d-f9c3-71c2-abb0-eed8f1b5e192@fjl.co.uk> References: <50dcf18d-f9c3-71c2-abb0-eed8f1b5e192@fjl.co.uk> X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.33; amd64-portbld-freebsd12.1) X-Clacks-Overhead: "GNU Terry Pratchett" Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Rspamd-Queue-Id: 4FBrbx11DTz3qYg X-Spamd-Bar: -- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=email-od.com header.s=dkim header.b=F+VlpTY5; dmarc=none; spf=pass (mx1.freebsd.org: domain of 4250.82.1d4cf000118fc81.b4ab05ac2da87643a5165d6e07fa11dd@email-od.com designates 142.0.176.198 as permitted sender) smtp.mailfrom=4250.82.1d4cf000118fc81.b4ab05ac2da87643a5165d6e07fa11dd@email-od.com X-Spamd-Result: default: False [-2.70 / 15.00]; MID_RHS_MATCH_FROM(0.00)[]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[email-od.com:s=dkim]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; FROM_HAS_DN(0.00)[]; RBL_DBL_DONT_QUERY_IPS(0.00)[142.0.176.198:from]; MV_CASE(0.50)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; DMARC_NA(0.00)[sohara.org]; RCPT_COUNT_ONE(0.00)[1]; SPAMHAUS_ZRD(0.00)[142.0.176.198:from:127.0.2.255]; RCVD_COUNT_THREE(0.00)[4]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; DKIM_TRACE(0.00)[email-od.com:+]; NEURAL_HAM_SHORT(-1.00)[-1.000]; NEURAL_HAM_LONG(-1.00)[-1.000]; FORGED_SENDER(0.30)[steve@sohara.org,4250.82.1d4cf000118fc81.b4ab05ac2da87643a5165d6e07fa11dd@email-od.com]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7381, ipnet:142.0.176.0/22, country:US]; FROM_NEQ_ENVFROM(0.00)[steve@sohara.org,4250.82.1d4cf000118fc81.b4ab05ac2da87643a5165d6e07fa11dd@email-od.com]; MAILMAN_DEST(0.00)[freebsd-questions] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 02 Apr 2021 20:04:14 -0000 On Fri, 2 Apr 2021 20:17:58 +0100 Frank Leonhardt wrote: > For longer than I care to remember (FreeBSD 2)  I've implemented a > physical asymmetric nat gateway using natd and ipfw. I just do what the > user guide says and it works. Yes it does and that's fine. > Am I using ipfw/natd for historical reasons? Can I do the same with pf? Yes you can the relevant line in my pf.conf is: nat on $ext_if inet from !($ext_if) -> ($ext_if:0) -- Steve O'Hara-Smith