Re: ipnat.conf oddity

From: Chris Faulhaber (jedgar@fxp.org)
Date: 06/18/01


Date: Mon, 18 Jun 2001 14:40:58 -0400
From: Chris Faulhaber <jedgar@fxp.org>
To: Chris Kesler <chris@pconline.com>


On Mon, Jun 18, 2001 at 01:34:13PM -0500, Chris Kesler wrote:
> This is my current ipnat.conf file.
>
> map vx0 192.168.1.0/24 -> 0/32 portmap tcp/udp 1025:65000
> map vx0 192.168.1.0/24 -> 0/32
>
> Notice that the address to the right of the -> is 0. I discovered by
> accident that this configuration works on my system. I'm using ipnat and
> ipf on 4.3-RELEASE.
>
> I couldn't find any docs describing why this config works. I have a cable
> modem connection, and the DHCP-assigned IP address changes once in a
> while. I wonder if this is a feature intended to allow me to continue to
> forward packets after my address changes. Or is it a bad idea to run the
> box this way?
>

See http://www.obfuscation.org/ipf/ipf-howto.txt

-- 
Chris D. Faulhaber - jedgar@fxp.org - jedgar@FreeBSD.org
--------------------------------------------------------
FreeBSD: The Power To Serve   -   http://www.FreeBSD.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • ipnat.conf oddity
    ... accident that this configuration works on my system. ... forward packets after my address changes. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: ipnat.conf oddity
    ... > accident that this configuration works on my system. ... > modem connection, and the DHCP-assigned IP address changes once in a ... 0/0 expands to "world", the whole net, and 0/32 expands to the interface ...
    (FreeBSD-Security)
  • Firewall
    ... My oppologies for not sending enough info. I'm using ipfw through ... rc.firewall with the "simple" configuration using NAT. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • (no subject)
    ... My oppologies for not sending enough info. I'm using ipfw through ... rc.firewall with the "simple" configuration using NAT. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: sendmail ; bogus letters
    ... D> Is there something I can do in the sendmail.cf file or other configuration ... D> change to drop these kinds of letters? ... MSFU LAN Admin ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)