tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: npf questions/experience migrating from ipf on NetBSD8

> wrote:
>>> After recompiling an GENERIC NetBSD 8_Stable kernel with npf
>>> pseudo-device, I could ping the internet from the console, but
>>> not from machines attached to my lan...
>>> Here are some diagnostics...
>>> # npfctl list -n
>>Is empty... no NAT taking place I can tell?
> How have you configured the machines on the lan ?

As you point out below, this is the map rule with ipf:
map wm0 -> 0/32 portmap tcp/udp 6970:65535

The internal router interface is (bge0)

This is a working (for > 10 years) ipnat/ipf setup...

>>I even tried a simple, promiscuous ruleset and that also fails to NAT?
>># npfctl show
>># filtering:    active
>># config:       loaded
>>procedure "log"
>>map wm0 dynamic any -> pass family inet4 from #
> You seem to be using for your lan, where does
> come into the equation ?
> I'm guessing that wm0 is your external interface, what is the IPv4
> address ?

Yeah...oddball setup...the "external", to the NetBSD router
interface, really is (wm0). (the only other member of this intermediate local net)
is the Comcast router and it is bidirectionally routing to and from a dynamic ip...

This part works fine, or at least does under ipnat/ipf...

Home | Main Index | Thread Index | Old Index