You can forward all trafic from the consumer gizmo internet facing
router (with single public IP address from the provider) to the
internal netbsd router.  It's usually called "DMZ host" in the web

I considered that but it seems insecure. I do have a few ports pointing to the device already though so that would just open all of them. I suppose it would be no worse than using the NetBSD box as my gateway router.

I will try your suggestions.

PS: Hmm, looking at gre(4), shouldn't the example be fixed to say

   ifconfig greN tunnel B C

I don't think so. I am pretty sure that I read that the first argument to tunnel must be an address on the host server. Not sure where I read that though as I have been doing a lot of research in the last day or two. I couldn't find it in the man page.

OK, found it. It was a statement in an email from kre@. Robert - can you give us a citation? Should the man page be updated?

