From owner-freebsd-questions@FreeBSD.ORG Mon May 9 22:42:07 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 240D916A4EC for ; Mon, 9 May 2005 22:42:07 +0000 (GMT) Received: from s001.searchy.nl (s001.searchy.nl [82.94.249.202]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8744943D3F for ; Mon, 9 May 2005 22:42:06 +0000 (GMT) (envelope-from ppi@searchy.net) Received: from [192.168.1.13] (53525E6F.cable.casema.nl [83.82.94.111]) by s001.searchy.nl (Postfix) with ESMTP id D67488DA32 for ; Tue, 10 May 2005 00:42:04 +0200 (CEST) Message-ID: <427FE73C.5080408@searchy.net> Date: Tue, 10 May 2005 00:42:04 +0200 From: Frank de Bot User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.5) Gecko/20041217 X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-questions@freebsd.org X-Enigmail-Version: 0.90.0.0 X-Enigmail-Supports: pgp-inline, pgp-mime Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Subject: ipfw + natd => some sites won't work :-S X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 09 May 2005 22:42:07 -0000 Hi, I got my FreeBSD set up to do nat, but it doesn't work 100%. Sites like Google for instance does work, but many other don't. All other protocols seems to be working properly. But why are sites failing to do anything? I got running natd with the verbose option and successfull request of google is indentical to a random other site :S The firewall I use is rather big. the most important piece is: 01200 723 652298 divert 8668 ip from any to 82.94.238.70 via fxp0 01200 521 85279 divert 8668 ip from 10.0.5.0/24 to any 01200 0 0 allow ip from any to 10.0.5.0/24 01201 524 85399 allow ip from 82.94.238.70 to any 01201 3 144 allow ip from any to 82.94.238.70 01500 871494 216106437 allow tcp from any to any established /etc/natd.conf is: alias_address %external_ip% verbose It just puzzles me why only some http request would fail and everything works fine! Anyone got any idea? Thanks in advanced, Frank de Bot