From owner-freebsd-net@FreeBSD.ORG Tue Jan 3 08:53:01 2012 Return-Path: Delivered-To: freebsd-net@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E5595106568D for ; Tue, 3 Jan 2012 08:53:01 +0000 (UTC) (envelope-from pprocacci@datapipe.com) Received: from EXFESMQ03.datapipe-corp.net (exfesmq03.datapipe.com [64.27.120.67]) by mx1.freebsd.org (Postfix) with ESMTP id 9F7B78FC1C for ; Tue, 3 Jan 2012 08:53:01 +0000 (UTC) Received: from nat.myhome (192.168.128.103) by EXFESMQ03.datapipe-corp.net (192.168.128.28) with Microsoft SMTP Server (TLS) id 14.1.339.1; Tue, 3 Jan 2012 03:42:10 -0500 Date: Tue, 3 Jan 2012 02:42:30 -0600 From: "Paul A. Procacci" To: Randy Bush Message-ID: <20120103084230.GC35878@nat.myhome> References: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) X-Originating-IP: [192.168.128.103] Content-Transfer-Encoding: quoted-printable Cc: freebsd-net Subject: Re: how to debug non-working hole in nat X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 03 Jan 2012 08:53:02 -0000 > add divert natd all from any to any via bridge0 This nat's all internal traffic on your lan. You probably don't want this.= I'd place the nat on the tun0 interface. Which leads me to.... If you machine receives a syn from the tun0 interface, what firewall rule i= s in place to redirect the packet to the nat instance? I do not see any. ~Paul ________________________________ This message may contain confidential or privileged information. If you are= not the intended recipient, please advise us immediately and delete this m= essage. See http://www.datapipe.com/about-us-legal-email-disclaimer.htm for= further information on confidentiality and the risks of non-secure electro= nic communication. If you cannot access these links, please notify us by re= ply message and we will send the contents to you.