From owner-freebsd-ipfw@FreeBSD.ORG Wed Jun 2 15:47:24 2004 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B3F1516A4D0 for ; Wed, 2 Jun 2004 15:47:24 -0700 (PDT) Received: from mail5.speakeasy.net (mail5.speakeasy.net [216.254.0.205]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6B67143D46 for ; Wed, 2 Jun 2004 15:47:24 -0700 (PDT) (envelope-from freebsd-ipfw.20.openmacews@spamgourmet.com) Received: (qmail 18977 invoked from network); 2 Jun 2004 22:47:24 -0000 Received: from ns1.presence-group.net (HELO [172.30.11.6]) (blakers@[216.27.177.134]) )encrypted SMTP for ; 2 Jun 2004 22:47:23 -0000 Date: Wed, 02 Jun 2004 15:47:21 -0700 From: OpenMacNews To: freebsd-ipfw Message-ID: <7D7540B64898043C025AFB23@[172.30.11.6]> In-Reply-To: <20040602154140.A17902@xorpc.icir.org> References: <20040602154140.A17902@xorpc.icir.org> X-Mailer: Mulberry/3.1.5 (Mac OS X) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline cc: Luigi Rizzo Subject: Re: does NATd _prevent_ use of stateful ipfw rules w/ keep-state? X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: OpenMacNews List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Jun 2004 22:47:24 -0000 > just about every sentence above is false. > > nothing prevents you from using stateful ipfw rules with natd, > _but_ you must understand very well the packet's flow and how > addresses are transformed or you won't get what you want. > > personally i see almost always only disadvantages (basically, it is much > easier to screw up your configuration) in using both because nat is > already stateful well, since I'm "not getting what I want" because I'm probably "screw(ing) up my configuration", I suppose this is good news ;-) thanks for the clarification! now, back to slogging through my config problems ... richard