user ppp's "nat proxy" under FreeBSD 5.1

From: Josh Osborne (dsbten.20.stripes_at_antichef.com)
Date: 07/28/03

  • Next message: Andy Gilligan: "Next-hop based on source address (IPv6)"
    Date: Mon, 28 Jul 2003 00:11:00 -0400
    To: freebsd-net@freebsd.org
    
    

    I'm using the user land ppp under 5.1 and I have this in the
    ppp.conf:

     nat enable yes
     nat log yes
     nat unregistered_only yes
     nat proxy type no_encode port 80 server 10.0.0.1:3128 proto tcp src 10.0.0.29

    before I execute the proxy line the web browser on 10.0.0.29 works
    fine, after it is dead in the water. (10.0.0.1 is the same machine
    that is running the user land ppp, and doing the NATing) The web
    proxy (squid) on 10.0.0.1 doesn't see any requests. To remove
    configuration of squid from the picture I just ran "ttcp -r -p
    3128" on 10.0.0.1. I attempted to use the web browser on 10.0.0.29
    agian, and got nothing (no connections to ttcp, and nothing in the
    web browser). When I just attempted to connect to 10.0.0.1:3128
    from a random port on 10.0.0.29 I saw the connection just fine.

    I built a copy of libalias and ppp with debugging on and set some
    breakpoints. The libalias code is definitly attempting to do
    *something* with the port 80 connections, but I can't really tell
    what.

    Is that proxy line roughly correct? Is it expected to work on 5.1?
    Am I smoking too much crack? Not enough? Is there a better way
    to do this anyway?
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Andy Gilligan: "Next-hop based on source address (IPv6)"

    Relevant Pages

    • RE: Request for feedback on ip-nat
      ... >to a im network to disconnect for no real apparent reason. ... Some 'cheap' NAT boxes will clear their connection cache, ... least the oldest connections, to conserve memory. ...
      (Security-Basics)
    • Re: sftp ls stalls with certain IP configurations
      ... >>sftp username@(from outside ... because NAT is evil: you are not getting full IP connectivity to the ... > Internet for your money. ... You will not be able to make any connections to ...
      (comp.security.ssh)
    • Re: switching a PIX to "no nat control"
      ... that be are forcing me to turn off NAT; ... that stateful connections to lower security interfaces will still ... But connections initiated to higher ... When you disable nat-control then you don't need statics anymore (I'm not ...
      (comp.dcom.sys.cisco)
    • Re: Demand-dial Interface and/or new Broadband connection?
      ... Review the article in the link below from Microsoft on how to configure NAT ... You should only have to create the network ... connections in "network connections" for NAT. ... > Internet through the Windows Server 2003 machine. ...
      (microsoft.public.windows.server.networking)
    • Re: [Full-Disclosure] NAT router inbound network traffic subversion
      ... You should probably clarify exactly what type of NAT implemenation ... > University whether it is possible to direct packets behind a NAT router ... > allow inbound connections with a preliminary request as he suggests, ...
      (Full-Disclosure)