Re: PF, DNS, and internal network

2006-06-12 Thread Chris Smith
On Friday 02 June 2006 17:39, Allen Theobald wrote: I can ping www.google.com from the firewall. But I cannot ping www.google.com from any computers on the internal network. Can you ping by IP address instead of by name? DNS queries should work just fine with that pf.conf. Do your clients

PF, DNS, and internal network -- solved

2006-06-05 Thread Allen Theobald
Greetings and thank you all for your replies. Thanks to all your suggestions I finally got it going with a caching DNS server. I understand this particular approach and am grateful to have it working. Being somehwat of a geek I am not content with merely getting it working, though! :^)

Re: PF, DNS, and internal network -- solved -- nevermind

2006-06-05 Thread Allen Theobald
In case anyone was going to answer this. :^) Forget this followup. In my rush to get an answer I didn't actually think about what I was asking at the end (thanks to Jeff Quast for pointing this out). Take care, Allen Tired of spam? Yahoo! Mail has the best spam protection around

Re: PF, DNS, and internal network

2006-06-03 Thread Craig Skinner
On Fri, Jun 02, 2006 at 02:39:23PM -0700, Allen Theobald wrote: Greetings everyone! This question has to do with PF and DNS from my internal network to my ISP. Here is what I have done: Set /etc/sysctl.conf net.inet.ip.forwarding=1 Set /etc/rc.conf pf=YES Used

PF, DNS, and internal network

2006-06-02 Thread Allen Theobald
Greetings everyone! This question has to do with PF and DNS from my internal network to my ISP. Here is what I have done: Set /etc/sysctl.conf net.inet.ip.forwarding=1 Set /etc/rc.conf pf=YES Used the pf.conf file from the FAQ (http://www.openbsd.org/faq/pf/example1.html).

PF, DNS, and internal network

2006-06-02 Thread Allen Theobald
Greetings everyone! Apologies in advance if this came through already. This question has to do with PF and DNS from my internal network to my ISP. Here is what I have done: Set /etc/sysctl.conf net.inet.ip.forwarding=1 Set /etc/rc.conf pf=YES Used the pf.conf file from the FAQ