Date: Sat, 1 Dec 2001 16:41:55 -0800 From: "Crist J . Clark" <cristjc@earthlink.net> To: Nick Rogness <nick@rogness.net> Cc: Sheldon Hearn <sheldonh@starjuice.net>, freebsd-questions@FreeBSD.ORG Subject: Re: Diagrams on natd? Message-ID: <20011201164155.L13613@blossom.cjclark.org> In-Reply-To: <Pine.BSF.4.21.0112011816310.48587-100000@cody.jharris.com>; from nick@rogness.net on Sat, Dec 01, 2001 at 06:23:21PM -0600 References: <20011201145441.H13613@blossom.cjclark.org> <Pine.BSF.4.21.0112011816310.48587-100000@cody.jharris.com>
next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, Dec 01, 2001 at 06:23:21PM -0600, Nick Rogness wrote: > On Sat, 1 Dec 2001, Crist J . Clark wrote: > > > On Wed, Nov 21, 2001 at 08:06:20PM +0200, Sheldon Hearn wrote: > > > > > > > > > On Wed, 21 Nov 2001 11:17:26 CST, Nick Rogness wrote: > > > > > > > I made an animated gif that steps through the nat process: > > > > > > > > http://freebsd.rogness.net/redirect.cgi?basic/nat.html > > > > > > > > As for the web page quoted above, it is a pretty good primer, but it > > gives some bad advice in the last section. The example is how to block > > incoming traffic on tcp/53. The example is bad for two reasons. First, > > blocking tcp/53 breaks DNS. > > Only zone transfers. Which is what the example was intended to > do. This is a common misconception. Blocking 53/tcp breaks queries too, but you don't see the problems it creates too frequently. > > Second, you are better off doing this > > _before_ the divert(4) rule. You are better off _blocking_ packets > > before the divert(4) rule whenever possible. That is, > > > > # ipfw add 40 deny tcp from any to 20.30.40.51 53 in via xl0 > > I agree, however,that is OK if you know what your public IP > is. In a natd-dynamic configuration. This was written just prior > to the release of the "me" flag in ipfw (I Believe). OK, # ipfw add 40 deny tcp from any to any 53 in via xl0 Is fine too. -- Crist J. Clark | cjclark@alum.mit.edu | cjclark@jhu.edu http://people.freebsd.org/~cjc/ | cjc@freebsd.org To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011201164155.L13613>