Current-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Revisiting: ipfilter/ipnat problems on -current



On Sun, Sep 07, 2008 at 08:29:04AM -0700, Paul Goyette wrote:
>>> The obvious solution might be "turn off
>>> ipfilter/ipnat" but I need ipnat - I don't have enough fixed IP
>>> addresses for everything - and I'm not willing to go out and buy a
>>> stand-alone device.  :)
>>
>> try pf instead?
>
> Got any example of how to make ipnat work with pf?  I thought that the  
> two (ipnat and ipfilter) were intimately tied together?

Rather than ipf.conf and ipnat.conf for ipf, you pop both the filtering
rules and the translation rules into pf.conf,
e.g., /usr/share/examples/pf/faq-example1 has some nat and rdr rules.
(Really, just look at pf.conf(5))

Cheers,

Patrick


Home | Main Index | Thread Index | Old Index