From owner-freebsd-questions Sun Jan 18 22:36:22 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id WAA00707 for questions-outgoing; Sun, 18 Jan 1998 22:36:22 -0800 (PST) (envelope-from owner-freebsd-questions@FreeBSD.ORG) Received: from yokogawa.soft.net (ybi-email-serv.yokogawa.soft.net [164.164.153.10]) by hub.freebsd.org (8.8.8/8.8.8) with SMTP id WAA00693 for ; Sun, 18 Jan 1998 22:36:02 -0800 (PST) (envelope-from s-mathew/Yokogawa_Blue_Star_Ltd/IN@yokogawa.soft.net) From: s-mathew/Yokogawa_Blue_Star_Ltd/IN@yokogawa.soft.net Received: by yokogawa.soft.net(Lotus SMTP MTA v1.06 (346.8 3-18-1997)) id E5256591.0024E313 ; Mon, 19 Jan 1998 12:12:54 +300600 X-Lotus-FromDomain: YBI-STP To: freebsd-questions@FreeBSD.ORG Message-ID: Date: Mon, 19 Jan 1998 12:12:44 +300600 Subject: Dual homed host Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk I've installed FreeBSD 2.2.5 on my Compaq Deskpro by anonymous FTP using an NE2000 card. I want to set up a firewall using a dual homed host. My second card is a DEC 21041 (Tulip). Since the kernel seems to support both cards, I just modified rc.conf to get the second card up as follows: #network_interfaces="ed0 lo0" # List of network interfaces (lo0 is loopback). network_interfaces="de0 ed0 lo0" # List of network interfaces (lo0 is loopback). ifconfig_de0="inet 172.30.1.83 netmask 255.255.0.0" ifconfig_ed0="inet 164.164.153.7 netmask 255.255.0.0" ifconfig_lo0="inet 127.0.0.1" # default loopback device configuration. 164.164.*.* is a network connected to the internet and 172.30.*.* is a private network. Both cards now work, but if I ping 164.164.153.7 from another machine on the 172.30 .*.* network, it replies ! (The other machine is a Windows NT workstation with the TCP/IP gateway set to 172.30.1.83) This should not happen since IP forwarding is supposed to be off by default. I verified that IP forwarding is off by using the sysctl utility - the value of net.inet.ip.forwarding is 0. What do I do to prevent this happening ? I'm attaching the following : 1) The output of dmesg (See attached file: dmesg) 2) The output of ifconfig -a -u (See attached file: ifconfig) 3) The output of netstat -r (See attached file: netstat) 4) rc.conf (See attached file: rc.conf) I'd really appreciate any help. Thank you. (uuencoded file dmesg follows) begin 644 dmesg M0V]P>7)I9VAT("AC*2`Q.3DR+3$Y.3<@1G)E94)31"!);F,N#0I#;W!Y2!O9B!#86QI9F]R;FEA+B`@06QL(')I M9VATB`U.#8M8VQA#4R8R`@4W1E<'!I;F<],3(-"B`@1F5A M='5R97,],'@Q8F8\1E!5+%9-12Q$12Q04T4L5%-#+$U34BQ-0T4L0U@X/@T* M71E2`](#$T-#,T,S`T("@Q-#`Y-DL@8GET97,I#0I0#(X,"TP>#(Y9B!I M#-F9B!I M#,W9B!I#-F-R!I71E&9F9F8P,#`P(&)R;V%D M8V%S="`Q-C0N,38T+C(U-2XR-34-"@EE=&AE&9F ),#`P,#`P(`T* ` end (uuencoded file netstat follows) begin 644 netstat M4F]U=&EN9R!T86)L97,-"@T*26YT97)N970Z#0I$97-T:6YA=&EO;B`@("`@ M("`@1V%T97=A>2`@("`@("`@("`@($9L86=S("`@("!2969S("`@("!5("`@("!50R`@("`@("`@("`P("`@("`@("`P(`T* ` end (uuencoded file rc.conf follows) begin 644 rc.conf M(R$O8FEN+W-H#0HC#0H-"B,@5&AI'`@)`T*#0HC(R,C(R,C M(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C M(R,C(R,C(R,C(PT*(R,C($EM<&]R=&%N="!I;FET:6%L($)O;W0M=&EM92!O M<'1I;VYS("`C(R,C(R,C(R,C(R,C(R,C(R,C(R,-"B,C(R,C(R,C(R,C(R,C M(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C(R,C M(R,C#0H-"G-W87!F:6QE/2).3R()"2,@4V5T('1O(&YA;64@;V8@2!A M9&1R97-S+@T*<&-C87)D7VEF8V]N9FEG/2).3R()(R!3<&5C:6%L:7IE9"!P M8V-A0T*=&-P7V5X=&5N7-L;V<@9&%E;6]N("AO7-L;V=D M7V9L86=S/2(B"0DC($9L86=S('1O('-Y2YD;VUA:6X@+6P@3TB3D\B"2,@4')O=FED92!.1E,@;VYL>2!O M;B!S96-U'1E;F1?96YA8FQE/2).3R()"2,@4G5N('1H92!8+3$P('!O=V5R M(&-O;G1R;VQL97(@9&%E;6]N+@T*>'1E;F1?9FQA9W,](B()"0DC($9L86=S M('1O('AT96YD("AI9B!E;F%B;&5D*2X-"@T*(R,C($YE='=O&YT<&0@3F5T M=V]R:R!4:6UE(%!R;W1O8V]L("AO&YT<&0@*&EF(&5N86)L960I+@T*=&EC:V%D:E]E;F%B M;&4](DY/(@D)(R!2=6X@=&EC:V%D:B`H;W(@3D\I+@T*=&EC:V%D:E]F;&%G M7!S971?96YA8FQE/2). M3R()"2,@4G5N('EP&9R9%]E;F%B;&4](DY/(@D) M(R!2=6X@&9R9"!A="!B;V]T('1I;64@*&]R($Y/*2X-"FYI&9R9"`H:68@96YA M8FQE9"DN#0IN:7-?>7!P87-S=V1D7V5N86)L93TB3D\B"2,@4G5N(')P8RYY M<'!A7!P87-S=V1D M7V9L86=S/2(B"0DC($9L86=S('1O(')P8RYY<'!A2`H;W(@3D\I+@T*7)A=&4](DY/(@D)(R!K97EB;V%R9"!R871E('1O.B!S;&]W+"!N;W)M M86PL(&9A6)E;&P](DY/(@D)(R!B96QL('1O(&1U M6-H86YG93TB3D\B"0DC(&9U;F-T:6]N(&ME>7,@9&5F875L="!V86QU97,@ M*&]R($Y/*2X-"F-U7!E('MN;W)M86Q\ M8FQI;FM\9&5S=')U8W1I=F5]("AO7-C;VYS+V9O;G1S+RH@*&]R($Y/*2X-"F)L86YK=&EM93TB M3D\B"0DC(&)L86YK('1I;64@*&EN('-E8V]N9',I(&]R(").3R(@=&\@='5R M;B!I="!O9F8N#0IS879E7!E('-E="DN M#0IM;W5S961?9FQA9W,](B()"2,@06YY(&%D9&ET:6]N86P@9FQA9W,@=&\@ M;6]U