From owner-freebsd-pf@FreeBSD.ORG Tue Sep 25 15:21:04 2007 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 5196D16A41A for ; Tue, 25 Sep 2007 15:21:04 +0000 (UTC) (envelope-from linux@giboia.org) Received: from fk-out-0910.google.com (fk-out-0910.google.com [209.85.128.191]) by mx1.freebsd.org (Postfix) with ESMTP id C08C013C459 for ; Tue, 25 Sep 2007 15:21:03 +0000 (UTC) (envelope-from linux@giboia.org) Received: by fk-out-0910.google.com with SMTP id b27so2377056fka for ; Tue, 25 Sep 2007 08:21:02 -0700 (PDT) Received: by 10.82.165.13 with SMTP id n13mr277095bue.1190733651122; Tue, 25 Sep 2007 08:20:51 -0700 (PDT) Received: by 10.82.135.11 with HTTP; Tue, 25 Sep 2007 08:20:51 -0700 (PDT) Message-ID: <6e6841490709250820i628855cbn54461cc9671d7f9b@mail.gmail.com> Date: Tue, 25 Sep 2007 12:20:51 -0300 From: "Gilberto Villani Brito" To: "Reinhard Haller" In-Reply-To: <46F819D2.5060904@interactive-net.de> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <46F819D2.5060904@interactive-net.de> Cc: freebsd-pf@freebsd.org Subject: Re: filtering local traffic on nat gateway X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Sep 2007 15:21:04 -0000 On 24/09/2007, Reinhard Haller wrote: > Hi, > > I want to restrict the locally generated outgoing traffic from the nat > gateway (cvsup, ddclient i.e. http + https, portupgrade i.e. ftp + http) > to the internet. > > How to distinguish forwarded traffic on tun0 from the local traffic > after natting? > > Thanks > Reinhard > > _______________________________________________ > freebsd-pf@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-pf > To unsubscribe, send any mail to "freebsd-pf-unsubscribe@freebsd.org" > Try this: block on $ext_if all pass in on $int_if from to any -- Gilberto Villani Brito System Administrator Londrina - PR Brazil gilbertovb(a)gmail.com