Date: Tue, 3 Nov 2015 00:44:19 +0100 From: Kristof Provost <kp@FreeBSD.org> To: Shawn Webb <shawn.webb@hardenedbsd.org> Cc: freebsd-current@freebsd.org Subject: Re: pf NAT and VNET Jails Message-ID: <089B842B-FE96-4016-BE6E-A63182422A9C@FreeBSD.org> In-Reply-To: <20151798.z4nmEG8eZc@hbsd-dev-laptop> References: <CAExMvs=jVsASLyiqU9nTpir0Hy_s_DfChgf4XKeGWv-8yojNBw@mail.gmail.com> <6607014.lfu2kQizLV@hbsd-dev-laptop> <D9FD5254-DA54-40B0-B4D6-71F65EB3B84A@FreeBSD.org> <20151798.z4nmEG8eZc@hbsd-dev-laptop>
next in thread | previous in thread | raw e-mail | index | archive | help
> On 02 Nov 2015, at 15:07, Shawn Webb <shawn.webb@hardenedbsd.org> = wrote: >=20 > On Monday, 02 November 2015 02:59:03 PM Kristof Provost wrote: >>=20 >> Can you add your pf.conf too? >>=20 >> I=E2=80=99ll try upgrading my machine to something beyond 290228 to = see if I can >> reproduce it. It=E2=80=99s on r289635 now, and seems to be fine. My = VNET jails >> certainly get their traffic NATed. >=20 > Sorry about that! I should've included it. It's pasted here: = http://ix.io/lLI >=20 > It's probably not the most concise. This is a laptop that can have one = of=20 > three interfaces online: re0 (ethernet on the laptop), wlan0 (you can = guess=20 > what that is), or ue0 (usb tethering from my phone). I used to be able = to=20 > specify NATing like that and pf would automatically figure out which = outgoing=20 > device to use. Seems like that's broken now. >=20 I=E2=80=99ve updated my machine and things still seem to be working. As you said, it=E2=80=99s probably related to the multiple nat entries. I=E2=80=99ll have to make a test setup, which=E2=80=99ll take a bit of = time, especially=20 since I=E2=80=99m messing with the host machine at the moment. Regards, Kristof
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?089B842B-FE96-4016-BE6E-A63182422A9C>