On Wed, Nov 26, 2008 at 12:52:47PM -0600, Patric wrote:
> ext_if = "xl2"
> int_if = "xl1"
> localnet = $int_if:network
> nat on $ext_if from $localnet to any -> ($ext_if)
> pass from { lo0, $localnet } to any keep state
> __
>
> this is pretty much the most basic natting p
On Wed, Nov 26, 2008 at 04:16:30PM -0600, Patric wrote:
> On Wed, 2008-11-26 at 14:37 -0500, Jason Dixon wrote:
> > On Wed, Nov 26, 2008 at 12:52:47PM -0600, Patric wrote:
> > > My current pf.conf
> > >
> > > __
> > > ext_if = "xl2"
> > > int_if = "xl1"
> > > localnet = $in
On Wed, Nov 26, 2008 at 12:52:47PM -0600, Patric wrote:
> My current pf.conf
>
> __
> ext_if = "xl2"
> int_if = "xl1"
> localnet = $int_if:network
> nat on $ext_if from $localnet to any -> ($ext_if)
> pass from { lo0, $localnet } to any keep state
>
Super Simple File ... but ...
Super Basic:
pfctl -ef /etc/pf.conf
If you reboot the system the rules start ? , and as Gary says pfctl -s ?
http://www.openbsd.org/faq/pf/index.html
Regards,
jv
Original-Nachricht
> Datum: Wed, 26 Nov 2008 12:04:09 -0800
> Von: Gary <[EMAI
: Wednesday, November 26, 2008 3:04 PM
> To: pf@benzedrine.cx
> Subject: Re: super simple pf.conf that doesn't work as expected.
>
>
> Have you tried defining $localnet explicitly? Also, what do you see with
> 'pfctl -s rules'?
>
> -Gary
>
# pfctl -vs ru
On Wed, 2008-11-26 at 14:37 -0500, Jason Dixon wrote:
> On Wed, Nov 26, 2008 at 12:52:47PM -0600, Patric wrote:
> > My current pf.conf
> >
> > __
> > ext_if = "xl2"
> > int_if = "xl1"
> > localnet = $int_if:network
> > nat on $ext_if from $localnet to any -> ($ext_if)
> > p
On Wed, 2008-11-26 at 12:52 -0600, Patric wrote:
> My current pf.conf
>
> __
> ext_if = "xl2"
> int_if = "xl1"
> localnet = $int_if:network
> nat on $ext_if from $localnet to any -> ($ext_if)
> pass from { lo0, $localnet } to any keep state
> __
>
>
On Wed, 2008-11-26 at 12:04 -0800, Gary wrote:
> Have you tried defining $localnet explicitly? Also, what do you see with
> 'pfctl -s rules'?
>
> -Gary
>
# pfctl -s rules
pass inet6 from ::1 to any flags S/SA keep state
pass on lo0 inet6 from fe80::1 to any flags S/SA keep state
pass inet from 1
and do you have ip forwarding enabled? (sysctl.conf)
net.inet.ip.forwarding=1
pfctl -vs rules
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of
Gary
Sent: Wednesday, November 26, 2008 3:04 PM
To: pf@benzedrine.cx
Subject: Re: super simple pf.conf that
Have you tried defining $localnet explicitly? Also, what do you see with
'pfctl -s rules'?
-Gary
My current pf.conf
__
ext_if = "xl2"
int_if = "xl1"
localnet = $int_if:network
nat on $ext_if from $localnet to any -> ($ext_if)
pass from { lo0, $localnet } to any keep state
__
this is pretty much the most basic natting pf.conf described in "The
B
11 matches
Mail list logo