From owner-freebsd-net Wed Feb 20 4:43:24 2002 Delivered-To: freebsd-net@freebsd.org Received: from mx1.dev.itouchnet.net (devco.net [196.15.188.2]) by hub.freebsd.org (Postfix) with ESMTP id C7B4437B405 for ; Wed, 20 Feb 2002 04:43:19 -0800 (PST) Received: from nobody by mx1.dev.itouchnet.net with scanned_ok (Exim 3.33 #2) id 16dW9N-000142-00 for freebsd-net@freebsd.org; Wed, 20 Feb 2002 14:47:09 +0200 Received: from shell.devco.net ([196.15.188.7]) by mx1.dev.itouchnet.net with esmtp (Exim 3.33 #2) id 16dW9M-00013c-00; Wed, 20 Feb 2002 14:47:08 +0200 Received: from bvi by shell.devco.net with local (Exim 3.33 #4) id 16dW8F-0009h7-00; Wed, 20 Feb 2002 14:45:59 +0200 Date: Wed, 20 Feb 2002 14:45:59 +0200 From: Barry Irwin To: Brendan Kosowski Cc: FreeBSD Networking Subject: Re: gateway question in relation to "RFC 1918" IP addresses Message-ID: <20020220144559.H25707@itouchlabs.com> References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from brendan@bmk.com.au on Wed, Feb 20, 2002 at 11:20:20PM +1100 X-Checked: This message has been scanned for any virusses and unauthorized attachments. X-iScan-ID: 4082-1014209229-47121@mx1.dev.itouchnet.net version $Name: REL_2_0_2 $ Sender: owner-freebsd-net@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Wed 2002-02-20 (23:20), Brendan Kosowski wrote: > > If I set up a FreeBSD box as a gateway, how do I tell it not to route > Private IP addresses ( ie. "RFC 1918" addresses ). You firewall them look at /etc/rc.firewall the standard option blocks the rfc 1918 addresses and a number of other spurious networks as mentioned in draft-manning-dusa-06.txt 9 IETF draft. Have a look at the man page for ipfw(8) should have all you need. Barry -- Barry Irwin bvi@itouchlabs.com +27214875150 Systems Administrator: Networks And Security Itouch Labs http://www.itouchlabs.com South Africa To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message