login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
openbsd-misc
»
2008
»
May
»
15
Re: pf-nat help
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: Gregory Edigarov
Subject:
Re: pf-nat help
Date: Thursday, May 15, 2008 - 6:00 am
Jesus Sanchez wrote:
quoted text
> Gregory Edigarov escribis: >> Jesus Sanchez wrote: >>> Hi, I'm using OpenBSD 4.2. >>> >>> I'm triying to get a very unsafe-simple ruleset to make a nat between a >>> laptop and my OpenBSD box. From my OpenBSD box I have two nics: >>> >>> OpenBSD box: >>> rl0 (witch gets a IP from dhcp and gets to the internet via ADSL) >>> sk0 (directly connected to the laptop via one cable) >>> >>> I seted the int_if ip statically as 192.168.1.1 (the laptop have >>> asigned >>> 192.168.1.2 and they see each other without problem, and I can do FTP >>> transfers and stuff like that) >>> >>> I have set the sysctl net.inet.ip.forwarding=1 >>> >>> my pf.conf (very unsafe and very simple, only to try this) >>> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- >>> >>> ext_if = "rl0" >>> int_if = "sk0" >>> localnetwork = "${int_if}:network" >>> >>> scrub in all >>> >>> nat on $ext_if from $localnetwork to any -> (ext_if) >>> >>> =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- >>> >>> then I make on the laptop (wich uses rl0): >>> >>> ifconfig rl0 inet 192.168.1.2 >>> >>> but in the laptop I don't have internet at all, it see the OpenBSD >>> box as 192.168.1.1 but nothing more. >>> >>> What I'm doing wrong? >>> >>> Thanks for your time >>> -Jesus >>> >>> >> nat pass on $ext_if from $localnetwork to any -> (ext_if) >> >> >> or, add these two lines to the end of your pf.conf: >> block all >> pass all >> > I tried that and still same thing. Nothing changes with theese rules. >
are you sure your pf is enabled? pfctl -e -- With best regards, Gregory Edigarov
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
Re: pf-nat help
, Jesus Sanchez
, (Thu May 15, 5:41 am)
Re: pf-nat help
, Gregory Edigarov
, (Thu May 15, 6:00 am)
Re: pf-nat help
, Jason Dixon
, (Thu May 15, 7:07 am)
Re: pf-nat help
, Karl Karlsson
, (Thu May 15, 1:29 pm)
Navigation
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Ingo Molnar
Re: [PATCH 0/3] v2 Make hierarchical RCU less IPI-happy and add more tracing
Jeremy Fitzhardinge
Re: Linux 2.6.28.10 and Linux 2.6.29.6 XEN Guest Support Broken x86_64 in BUILD
Nick Piggin
Re: [patch] CFS (Completely Fair Scheduler), v2
Gary Hade
Re: [PATCH 0/5][RFC] Physical PCI slot objects
Dave Johnson
Re: expected behavior of PF_PACKET on NETIF_F_HW_VLAN_RX device?
linux-netdev
:
Arnd Bergmann
Re: 64-bit net_device_stats
Stephens, Allan
RE: [PATCH]: tipc: Fix oops on send prior to entering networked mode
frank.blaschka
[patch 3/5] [PATCH] qeth: support z/VM VSWITCH Port Isolation
Wu Fengguang
Re: [PATCH] dm9601: handle corrupt mac address
David Miller
Re: [PATCH net-2.6.24] Fix refcounting problem with netif_rx_reschedule()
git
:
Junio C Hamano
Re: [PATCH] [RFC] add Message-ID field to log on git-am operation
Junio C Hamano
Re: Handling large files with GIT
Karl
Re: [ANNOUNCE] pg - A patch porcelain for GIT
Josh Triplett
Re: [RFC][PATCH 00/10] Sparse: Git's "make check" target
Pierre Habouzit
Re: [PATCH] git-daemon: more powerful base-path/user-path settings, using formats.
git-commits-head
:
Linux Kernel Mailing List
MIPS: RBTX4939: Fix IOC pin-enable register updating
Linux Kernel Mailing List
regulator: update email address for Liam Girdwood
Linux Kernel Mailing List
[SCSI] ipr: add message to error table
Linux Kernel Mailing List
powerpc/32: Wire up the trampoline code for kdump
Linux Kernel Mailing List
USB: omap_udc: sync with OMAP tree
openbsd-misc
:
Josh Grosse
Re: error : pkg add phpMyAdmin
Brian Candler
Re: OBSD's perspective on SELinux
Jacob Meuser
Re: /dev/audio: Device busy
David Vasek
Re: Inexpensive, low power, "wall wart" computer
William Boshuck
Re: Richard Stallman...
Colocation donated by:
Syndicate