Re: natd / ipfw services on internal interface (Ivan Voras)

2007-09-14 Thread Joe
Joe wrote: > I have a question about natd/ and ipfw. I am running natd on my external > interface and I have some services on my internal interface. > > The services seem to be getting their ip addresses nat'd and some of them > work and some of them dont. > > Any idea how to prevent

Re: natd / ipfw services on internal interface

2007-09-10 Thread Ivan Voras
Joe wrote: I have a question about natd/ and ipfw. I am running natd on my external interface and I have some services on my internal interface. The services seem to be getting their ip addresses nat'd and some of them work and some of them dont. Any idea how to prevent things from going in

Re: natd, ipfw problem

2005-03-04 Thread Ean Kingston
It's been a while but I'll see if I can help out. On Friday, March 4, 2005, at 06:52 PM, Florian Hengstberger wrote: Hi! Tell me if I should post this otherwhere. Given two network cards sis0 (external) and vr0 (internal) I'm trying to give my girlfriend access to the web. Her ip is 192.168.0.2, I

Re: natd, ipfw and MS netmeeting

2004-06-04 Thread Christoph P. Kukulies
On Fri, Jun 04, 2004 at 07:37:15AM +0800, Khairil Yusof wrote: > On Thu, 2004-06-03 at 11:26 +0200, Christoph Kukulies wrote: > > > Anyway, the prsent (simple) natd rules don't seem to suffice. > > If I'm not wrong, ms netmeeting and msn messenger (audio,video) do not > work over nat. There are s

Re: natd, ipfw and MS netmeeting

2004-06-03 Thread Christian Hiris
On Thursday 03 June 2004 11:26, Christoph Kukulies wrote: > I have problems getting a MC netmeeting seession established > across a FreeBSD gateway (5.2-current). > > Anyway, the prsent (simple) natd rules don't seem to suffice. > In most cases you want to use username to ip mapping and a proxy, i

Re: natd, ipfw and MS netmeeting

2004-06-03 Thread Khairil Yusof
On Thu, 2004-06-03 at 11:26 +0200, Christoph Kukulies wrote: > Anyway, the prsent (simple) natd rules don't seem to suffice. If I'm not wrong, ms netmeeting and msn messenger (audio,video) do not work over nat. There are some third party windows utilities available to enable this to work. I have

Re: natd + ipfw - very slow internet for LAN users

2004-03-12 Thread Kenneth Culver
o any keep-state via ${iif} Btw, i have a static internet ip address, not the dynamic. I have read the man ipfw BUGS section, but still I can't understand, how can i solve my problem. - Original Message - From: "jon" <[EMAIL PROTECTED]> To: "Prodigy" <[EMAIL

Re: natd + ipfw - very slow internet for LAN users

2004-03-12 Thread Prodigy
tate via ${iif} Btw, i have a static internet ip address, not the dynamic. I have read the man ipfw BUGS section, but still I can't understand, how can i solve my problem. - Original Message - From: "jon" <[EMAIL PROTECTED]> To: "Prodigy" <[EMAIL PROTECTED]&

Re: natd + ipfw - very slow internet for LAN users

2004-03-10 Thread Prodigy
> Ping to an ip address does not use DNS. > What is response time when you use ping domain name? It's ~250ms for google.com and other domains (good enough too). > I see you have forced ip address for your nic card connected to the > public internet by using rc.conf statement. > This looks wrong to

Re: natd & ipfw

2003-12-07 Thread Lewis Thompson
On Sun, Dec 07, 2003 at 01:11:40PM +0300, Lev Klimin wrote: > then natd don't change source address, and ping don't work. I thinked > that natd must do NAT whenever and wherever it work. May I be > mistaken? You may be. I had a problem a few months ago that seemed very similar. In the end I gave

Re: NATD & IPFW

2003-04-02 Thread Ryan Merrick
Brian McCann wrote: Hi all. I'm having an issue with security while trying to get natd to work with ipfw. I got my ipfw rules working great, so I added the natd line in: ipfw add divert 8668 all from any to any via $EXTERNAL_INTERFACE But I can't do anything (ping, fetch, etc) until I add: ip

RE: NATD & IPFW

2003-04-01 Thread Mark-Nathaniel Weisman
The entry I added to my ruleset was: # Allow outbound pings ipfw add pass icmp from any to any in recv $external icmptypes 0 ipfw add pass icmp from any to any out xmit $external icmptypes 8 # Allow outbound traceroutes ipfw add pass icmp from any to any in recv $internal i