Subject: Re: IPNAT problems
To: Xiamin Raahauge <xiamin@scdesantis.ne.mediaone.net>
From: Dave Huang <khym@bga.com>
List: netbsd-help
Date: 11/19/1997 15:45:53
On Wed, 19 Nov 1997, Xiamin Raahauge wrote:
> I've been using IPNAT for a while now, but recently (after I upgraded to
> 1.3_ALPHA, I think) it ceased working. As far as I know, nothing changed
> in my configuration, except that the binaries are newer, and the kernel
> was made with a different config file (I lost the old one, so I might not
> have the right options in it, but I think I have the right ones).
> 
> Here's the output from ipnat -l:
> List of active MAP/Redirect filters:
> map sn0 10.0.0.0/24.0.0.0 -> 24.128.90.56/0  portmap tcp/udp 512:0
> 
> List of active sessions:
> 
> This is my /etc/ipnat.conf file:
> map sn0 10.0.0.0/8 -> 24.128.90.56/32 portmap tcp/udp 10000:20000

Are you sure your ipf/ipnat binaries are in sync with the version of
ipfilter in the kernel? ipnat -l should show the same stuff as
/etc/ipnat.conf. I don't know how to check the versions though...

> options         IPFILTER
> options         PFIL_HOOKS

BTW, are these actually used anywhere? I seem to remember that PFIL_HOOKS
is no longer needed, and I don't think IPFILTER was ever needed... but I
could be wrong :)
--
Name: Dave Huang     |   Mammal, mammal / their names are called /
INet: khym@bga.com   |   they raise a paw / the bat, the cat /
FurryMUCK: Dahan     |   dolphin and dog / koala bear and hog -- TMBG
Dahan: Hani G Y+C 22 Y++ L+++ W- C++ T++ A+ E+ S++ V++ F- Q+++ P+ B+ PA+ PL++