Subject: Re: Setting up a firewall with ipf
To: Dave Huang <khym@azeotrope.org>
From: Manuel Bouyer <bouyer@antioche.lip6.fr>
List: netbsd-help
Date: 01/10/2001 19:50:37
On Tue, Jan 09, 2001 at 04:20:16PM -0600, Dave Huang wrote:
> I recently got an ADSL line and a block of 8 IP addresses, and was
> wondering if there was a way to use ipf to filter packets without also
> doing NAT. My firewall machine is running NetBSD 1.5, and has 3
> interfaces: ne0 - an ethernet for my LAN, ne1 - an ethernet to the ADSL
> bridge, and ray0 - an Aviator2.4 wireless. Currently, I've assigned all
> 8 of my IP addresses to ne1, 10.1.1.0/24 addresses to the machines on my
> LAN, and 10.1.2.0/24 to the wireless machines. I've got ipf filtering
> stuff coming in on ne1, and ipnat's bimap mapping between the internal
> 10.* addresses and the external addresses. This pretty much works, but
> I'd rather let my machines use their actual addresses, if possible.
> Apparently, I can do this with OpenBSD's bridging, but NetBSD doesn't
> do that yet... is there any other way to do what I want?

I think there are userland bridging software in pkgsrc but I've never used
them.

--
Manuel Bouyer <bouyer@antioche.eu.org>
--