Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 18 Oct 2000 14:11:21 -0400
From:      "Peter Brezny" <peter@sysadmin-inc.com>
To:        <freebsd-security@freebsd.org>
Subject:   natd/ipfw and mpd-netgraph for VPN question
Message-ID:  <000901c0392e$d23150a0$47010a0a@fire.sysadmininc.com>

next in thread | raw e-mail | index | archive | help
suppose i've got two offices at different locations, each with a cable modem
or other 'fast' access using mpd-netgraph on a 4.1 box to create a vpn
between them.  each office uses their connection to go to the internet as
well.

Now i need to firewall each connection to the internet.  Will natd/ipfw be
able to play nice with mpd-netgraph?

the natd man page says that

options IPFIREWALL
options IPDIVERT

must be compiled into the kernel however just the line

firewall_enable="YES"

aparently starts a kernel module for ipfw...is that line in rc.conf enough
or does natd really require a recompiled kernel?

and finally, would i be better off with a package like SOCKS5 instead of
natd/ipfw and would it get along as well with mpd-netgraph?



Thanks for your help.


Peter Brezny
SysAdmin Services, Inc.



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?000901c0392e$d23150a0$47010a0a>