Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 11 Aug 2010 15:35:56 -0700
From:      Serguey Parkhomovsky <xindigo@gmail.com>
To:        freebsd-pf@freebsd.org
Subject:   pf doesn't honor net.inet.ip.forwarding?
Message-ID:  <AANLkTinHPBYGM7awcT6wCu1NqvBmt2aTz9j=giSkGvH3@mail.gmail.com>

next in thread | raw e-mail | index | archive | help

Hello,

pf seems to do NAT forwarding whether or not net.inet.ip.forwarding is
enabled. I set up a NAT between my webserver jail on lo1 and my
external interface on em0, and it works even when this setting is
disabled.

Here is the relevant part of my pf.conf:
nat on em0 from lo1 to any -> (em0)

Why does this work? Shouldn't pf be unable to forward packets when
net.inet.ip.forwarding=0?

- Serguey



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?AANLkTinHPBYGM7awcT6wCu1NqvBmt2aTz9j=giSkGvH3>