From owner-freebsd-questions@FreeBSD.ORG Mon Jul 18 15:55:40 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0FBFC16A41C for ; Mon, 18 Jul 2005 15:55:40 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from pi.codefab.com (pi.codefab.com [199.103.21.227]) by mx1.FreeBSD.org (Postfix) with ESMTP id 67B7743D48 for ; Mon, 18 Jul 2005 15:55:37 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from localhost (localhost [127.0.0.1]) by pi.codefab.com (Postfix) with ESMTP id 968855E00; Mon, 18 Jul 2005 11:55:36 -0400 (EDT) Received: from pi.codefab.com ([127.0.0.1]) by localhost (pi.codefab.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 65516-09; Mon, 18 Jul 2005 11:55:26 -0400 (EDT) Received: from [192.168.1.3] (pool-68-161-54-113.ny325.east.verizon.net [68.161.54.113]) by pi.codefab.com (Postfix) with ESMTP id BF1FF5D41; Mon, 18 Jul 2005 11:55:25 -0400 (EDT) Message-ID: <42DBD0F5.9070407@mac.com> Date: Mon, 18 Jul 2005 11:55:33 -0400 From: Chuck Swiger Organization: The Courts of Chaos User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.8) Gecko/20050511 X-Accept-Language: en-us, en MIME-Version: 1.0 To: DerAlSem References: <1556383370.20050718141952@deralsem.com> <42DBC7D6.4060305@mac.com> <432433990.20050718192334@deralsem.com> In-Reply-To: <432433990.20050718192334@deralsem.com> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: amavisd-new at codefab.com Cc: freebsd-questions@freebsd.org Subject: Re: Real IP under NAT X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Jul 2005 15:55:40 -0000 DerAlSem wrote: > Hello Chuck, [ ... ] > No, that won't work, because i need an external IP on LAN machine. > > Ext IP adresses - 1.2.3.1-1.2.3.5 > Gate ext_if - 1.2.3.1 > Gate int_if - 192.168.0.1 > LAN (via NAT) machines - 192.168.0.2-20 > Another LAN (via NAT) machine - 1.2.3.2 > > How? natd doesn't care whether you use routable or non-routable IPs; you can NAT an external IP, too, if you really want to. But if you simply want to set up a small DMZ where the hosts are not doing NAT but just using routable IP's, that's trivial: set gateway_enable in /etc/rc.conf, and away you go. In this case, you'd want three interfaces on the box, a WAN, a LAN, and a DMZ, preferably all on distinct subnets. -- -Chuck