Subject: Re: ipf / nat woes on PMAX?
To: Jochen Kunz <jkunz@unixag-kl.fh-kl.de>
From: Todd Vierling <tv@wasabisystems.com>
List: port-pmax
Date: 03/26/2002 16:06:29
On Tue, 26 Mar 2002, Jochen Kunz wrote:

: My internal network is connected to le1, le0 is the connection to the
: world (static IP, permanent connection). I am using the tunnel device
: tun0 with vtund 2.5b1 for a VLAN like setup. ipf is enabled, no rules
: are loaded, ipnat has a mapping
: bimap tun0 192.168.1.4/32  -> 1.2.3.4/32
: that works as expected. But if I change the mapping to
: bimap le1 192.168.1.4/32  -> 1.2.3.4/32
: i.e. the mapping is moved from the tun0 interface to le1, it does not
: work. It seams that le1 completely ignores any NAT mappings.

Mappings are typically put on the *outside* interface.  So if you wanted to
move the mapping from vlan to the standard net connection, it would be on
le0, not le1....

-- 
-- Todd Vierling <tv@wasabisystems.com>  *  Wasabi & NetBSD:  Run with it.
-- CDs, Integration, Embedding, Support -- http://www.wasabisystems.com/