Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 20 Oct 1998 17:49:14 -0700 (PDT)
From:      Julian Elischer <julian@whistle.com>
To:        Dan Langille <junkmale@xtra.co.nz>
Cc:        Dan Busarow <dan@dpcsys.com>, Matt Prigge <prigge@bucknell.edu>, FreeBSD Questions List <freebsd-questions@FreeBSD.ORG>
Subject:   Re: More IPFW/natd trouble, but I'm close!
Message-ID:  <Pine.BSF.3.95.981020174557.16317F-100000@current1.whistle.com>
In-Reply-To: <199810201948.IAA17502@cyclops.xtra.co.nz>

next in thread | previous in thread | raw e-mail | index | archive | help
WARNING!
this changes in 3.0:

On Wed, 21 Oct 1998, Dan Langille wrote:

> On 20 Oct 98, at 10:03, Dan Busarow wrote:
> >   packets before they are dropped by the firewall.  The firewall rules
> >   ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ will be run again on
> >   each packet after translation by natd, minus any divert rules.
> 

On 3.0 the rules are restarted at the first rule after the divert rule..

1 sdafasdf asdf sa asdf as
2 divert xxxx ip from any to any in rcv ed0
3 blah blah blah


the order of the rules will be:

1
2 divert
2a translated packet reinjected AFTER rule 2
3


julian





To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.95.981020174557.16317F-100000>