Re: binat question

2008-05-13 Thread Trevor Talbot
On May 12, 2008, at 2:32 PM, Christer Solskogen wrote: If I do not use the binat-rule, connecting to games (in CoH) will not work. But CoH also seems to be the only game with that kind of problem. IF the ports are right shouldn't this be enough? CoH_ports = { 6112 , 9100 , 30260 } rdr

Re: binat question

2008-05-13 Thread Christer Solskogen
Karl O. Pinc wrote: On 05/12/2008 04:32:05 PM, Christer Solskogen wrote: If I do not use the binat-rule, connecting to games (in CoH) will not work. But CoH also seems to be the only game with that kind of problem. If I am not mistaken, using a binat-rule also makes my machine vurnable for

Re: binat question

2008-05-13 Thread Matthew Rowley
You report what does work, but not what didn't work so it's difficult to say why it didn't work. I really should have done that. If I do not use the binat-rule, connecting to games (in CoH) will not work. But CoH also seems to be the only game with that kind of problem. If I am not

Re: binat question

2008-05-13 Thread Karl O. Pinc
On 05/13/2008 12:35:28 AM, Christer Solskogen wrote: This is my full pf.conf: The only thing I notice offhand is that I prefer to put the ftp-proxy anchors above all the other translation rules so that whatever magic ftp-proxy is working does not get inadvertently preempted. (I don't know

Re: binat question

2008-05-13 Thread jared r r spiegel
On Mon, May 12, 2008 at 11:44:29PM -0700, Trevor Talbot wrote: You might also need to use the static-port option for udp nat rules: nat pass log on $ext_if proto udp from $funshine port $COH_ports to any - 85.200.10.151 static-port yeah, i was gonna say static port too, but trevor beat me

Re: binat question

2008-05-12 Thread Karl O. Pinc
On 05/12/2008 04:32:05 PM, Christer Solskogen wrote: If I do not use the binat-rule, connecting to games (in CoH) will not work. But CoH also seems to be the only game with that kind of problem. If I am not mistaken, using a binat-rule also makes my machine vurnable for other stuff. I am

Re: binat question

2008-05-12 Thread Karl O. Pinc
On 05/12/2008 12:07:45 PM, Christer Solskogen wrote: I have been trying to get some of my online games to work. Normally on a NAT-ed network rdr's are needed to get the port forwarding to work. My pf.conf is: funshine = 192.168.0.12 rdr pass log on $ext_if proto { tcp, udp } from any to

Re: binat question

2008-05-12 Thread Christer Solskogen
Karl O. Pinc wrote: On 05/12/2008 12:07:45 PM, Christer Solskogen wrote: I have been trying to get some of my online games to work. Normally on a NAT-ed network rdr's are needed to get the port forwarding to work. My pf.conf is: funshine = 192.168.0.12 rdr pass log on $ext_if proto { tcp,

Re: Binat question

2006-09-28 Thread charles Collin
Martin Toft a écrit : charles Collin wrote: # NAT section binat on ext_if from 10.0.0.B to any - X.Y.Z.B # Rules section, i only need https access to this machine. block all . . . pass in on ext_if proto tcp from any to X.Y.Z.B port https pass out in dmz_if proto tcp from any to