Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 14 Nov 2000 07:44:05 -0500 (EST)
From:      Matthew George <mdg@mdgnet.org>
To:        Wim Olivier <wimo@osiricom.co.za>
Cc:        FreeBSD-stable <freebsd-stable@freebsd.org>
Subject:   Re: IPFW issue on FBSD 4.0-REL
Message-ID:  <Pine.BSF.4.21.0011140741230.7789-100000@madness.mdgnet.org>
In-Reply-To: <3A111F5B.6E7EBDD@osiricom.co.za>

next in thread | previous in thread | raw e-mail | index | archive | help
correct

you need a divert rule for natd ... something along the lines of:

add 100 divert natd ip from any to any via <NATD INTERFACE>

see /etc/rc.firewall, natd(8)

On Tue, 14 Nov 2000, Wim Olivier wrote:

> Date: Tue, 14 Nov 2000 13:17:48 +0200
> From: Wim Olivier <wimo@osiricom.co.za>
> To: FreeBSD-stable <freebsd-stable@freebsd.org>
> Subject: IPFW issue on FBSD 4.0-REL
> 
> Hi everyone,
> 
> Made some progress now.
> 
> I set firewall_enable to NO in /etc/rc.conf and reboot the system.
> When it comes up no ipfw rules are loaded.  I then load the following
> rule:
> 
> My IPFW fules now look like this: (and it works) - BUT i can only access
> the Net from the BSD box itself!
> 
> 65001 2027 133645 allow ip from any to any via any
> 65535  110   8824 deny ip from any to any
> 
> No LAN PC's are able to get past the BSD nat nic.
> 
> 
> --
> Kind Regards,
> 
> Wim Olivier
> Principal Consultant - UNIX Systems
> Professional Services (Africa & Middle East)
> OSIRICOM Holdings (Pty) Ltd.  -  South Africa
> Mobile : +27 (0) 82 6553599            http://www.osiricom.co.za
> Tel      : +27 11 802 7415
> Fax     : +27 11 802 5853
> 
> 

-- 




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0011140741230.7789-100000>