Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 26 Nov 2002 09:03:53 -0800
From:      "Drew Tomlinson" <drew@mykitchentable.net>
To:        "Alvaro Rosales R." <aran80@wintersperu.com.pe>, =?iso-8859-1?Q?Flemming_Fr=F8kj=E6r?= <flemming@froekjaer.org>
Cc:        <freebsd-questions@FreeBSD.ORG>
Subject:   Re: NAT + IPFW question
Message-ID:  <033601c2956d$cce57980$6e2a6ba5@tagalong>
References:  <1038328197.3de3a185e675d@mail.froekjaer.org>

next in thread | previous in thread | raw e-mail | index | archive | help
----- Original Message -----
From: "Flemming Frøkjær" <flemming@froekjaer.org>
To: "Alvaro Rosales R." <aran80@wintersperu.com.pe>
Cc: <freebsd-questions@FreeBSD.ORG>
Sent: Tuesday, November 26, 2002 8:29 AM
Subject: Re: NAT + IPFW question


> Alvaro Rosales R. wrote:
> > Hi fellows I have setup natd in my freeBSD BOX (using firewall
=OPEN)
> > and it is working fine.
> > Now I want to close my firewall so that the only computer that is
using
> > NATD would the the only one that could accept connections from the
> > internet.But when I try to telnet to the natd box I cant connect to
it.What
> > Am I doing wrong?
> > Those are   my  ipfw rules
> > 10.10.1.91 (natd box)
> > 10.10.1.2 (my box)
> >
> > 00050   5816  2829686 divert 8668 ip from any to any via rl1
> > 00100   2412   168334 allow ip from any to any via lo0
> > 00200      0        0 deny ip from any to 127.0.0.0/8
> > 00300      0        0 deny ip from 127.0.0.0/8 to any
> > 00800   5609  6342173 allow ip from 10.10.1.91 to 130.102.1.2
> > 00801   3580   143970 allow ip from 10.10.1.2 to 130.102.1.91
> > 01000 430772 59326512 deny ip from any to any
> > 65000      0        0 allow ip from any to 10.10.1.2
> > 65535  17161  5967606 allow ip from any to any
> >
> > To Unsubscribe: send mail to majordomo@FreeBSD.org
> > with "unsubscribe freebsd-questions" in the body of the message
>
> You need to tell natd to forward port 23 (telnet) to 10.10.1.2
> man natd

This is only necessary if the poster wants to connect to "his box".  As
I understand it, he wishes to telnet to the natd box which is
10.10.1.91.  In this case, no forward is required.

Cheers,

Drew

> \Flemming
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-questions" in the body of the message
>
>


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?033601c2956d$cce57980$6e2a6ba5>