RE: Ipnat RDR broken?

This is a discussion on RE: Ipnat RDR broken? within the IPFilter forums, part of the System Security and Security Related category; On Sat, 3 Jul 2004, Dave Raven wrote: > Anyone got any ideas on this? > The one system I ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-03-2004
Laurence Moore
 
Posts: n/a
Default RE: Ipnat RDR broken?



On Sat, 3 Jul 2004, Dave Raven wrote:

> Anyone got any ideas on this?
>


The one system I put into production in a bridge configuration albeit
transparent, does not require ipnat rules, simply using ipf
rules was all that was required (OpenBSD system).

Cheers,

Larry.

> Thanks
> Dave
>
> -----Original Message-----
> From: owner-ipfilter@coombs.anu.edu.au
> [mailto:owner-ipfilter@coombs.anu.edu.au] On Behalf Of Dave Raven
> Sent: 29 June 2004 06:11 PM
> To: ipfilter@coombs.anu.edu.au
> Subject: Ipnat RDR broken?
>
>
> Hi all,
> I'm trying to redirect port 25 traffic to myself on a bridge'd
> freebsd machine in both directions, I have no problem doing it with ipnat
> when its on the 172.50 card (its range is /25) however 172.51 is on another
> card (/32 as its an alias) and the redirection doesn't work there. If I swop
> the masks around it does work - if I disable it I can telnet to both 51 and
> 50. Having done some serious research I've found that my problem has
> been lying in ipnat - I tried with ipfw and it worked first time. Below is
> my bridge setup, and my ipnat rules (broken) and my ipfw rules (working).
> Any ideas?
>
> # sysctl -a|grep bridge
> net.link.ether.bridge_cfg: em1,em0
> net.link.ether.bridge: 1
> net.link.ether.bridge_ipfw: 1
> net.link.ether.bridge_ipf: 1
>
> Ipnat rules:
> rdr em1 0.0.0.0/0 port 25 -> x.y.172.50 port 25 tcp
> rdr em0 0.0.0.0/0 port 25 -> x.y.172.51 port 25 tcp
>
> Ipfw rules:
> ipfw add 1 fwd 127.0.0.1:25 tcp from any to any 25 in
>
> Thanks
> Dave
>
>
>
>
>


Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:48 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0