Subject: Re: NAT Trouble
To: Rasmus Wiman <rasmus@ebox.tninet.se>
From: None <h.Hoppe@ind.tno.nl>
List: port-i386
Date: 10/26/1998 13:35:06
Rasmus Wiman wrote:
> [...]
> Actually, this confuses me a lot! I thought that the purpose of ifp was to do
> the gatewaying instead of the kernal, thus providing the filtering/translation
> required for firewalling/NAT. Who knows, my network might be wide open to
> attackers!

Actually, it should be possible to keep the GATEWAY option off in the
kernel and use the fastroute option of ipf instead.
On the other hand, fastroute doesn't seem quite stable yet. My better half
tried to get a fastrouted filter working on 1.3.2; much lossage ensued.

Greetings,
      - Hans