NAT+IPFW

From: Jer (jeremy_at_multihaven.org)
Date: 05/23/03

  • Next message: ddg: "VPN IPSEC WIRELESS"
    Date: Thu, 22 May 2003 18:22:31 -0400
    To: freebsd-security@freebsd.org
    
    

    Dear all

    I need to do the following

    I have a fbsd router that runs nat and routes some public IP addresses

    I ned to use the ipfw rules to deny traffic from the public IP's AND the
    nat o do bandwidth limiting

    eg
    deny tcp from 192.168.200.1 to www.yahoo.com http out
    and
    deny tcp from 24.199.213.1 to www.yahoo.com http out

    my questions are where do I place the rules in relation to the divert rules etc

    Thanks

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: ddg: "VPN IPSEC WIRELESS"

    Relevant Pages

    • Bei HTTP NAT obwohl Route eingestellt ist?
      ... eingestelltes Netzwerkverhältnis ist 'Route'. ... über HTTP jedoch mit seiner eigenen IP maskiert (also NAT macht). ... Die Clients sind SecureNAT Clients und haben keinen Proxyeintrag im ...
      (microsoft.public.de.german.isaserver)
    • Re: Was =?ISO-8859-1?Q?st=F6rt_da_nachts_im_Bereich_1=2E?= =?ISO-8859-1?Q?4_-_1=
      ... kommt kein Virus am NAT vorbei, ... die "Schädlinge" aber per HTTP, ... Ich weiss nur, dass ich NAT habe und die Firewall zwar nicht oft, aber doch einige Male die Bremse zog. ...
      (de.sci.electronics)
    • Re: a problem with nat table setting
      ... I am having a problem with the nat table configuration. ... I have found that if there is a established connection exist between ... linux PC and the webserver before I start the proxy, ... http packet will not be passed to the proxy, ...
      (comp.os.linux.misc)
    • Re: NATD and Address Redirection
      ... >> Could you check if TELNET, HTTP, or SSH from the outside world to ... The problem may have to do with VNC ... >> protocol peculiarities preventing it from working through NAT. ...
      (freebsd-hackers)