Re: NAT problem with public network

From: Nickolay A. Kritsky (nkritsky_at_star-sw.com)
Date: 12/16/04

  • Next message: KC Somaratne: "HP NC7170 Dual Port PCI-X 1000T Gigabit Server Adapter"
    Date: Thu, 16 Dec 2004 14:45:26 +0300
    To: John Angelmo <john@veidit.net>
    
    

    Hello John,

    You can use two ways:
    1. Add 'unregistered_only yes' to your natd.conf
    2. Run natd on xl2 with -reverse option

    If I were you I would do the first one.

    Thursday, December 16, 2004, 1:06:03 PM, John Angelmo wrote:

    JA> Hello

    JA> I have a network setup like this:

    JA> xl0: External:213.115.251.220
    JA> xl1: DMZ: 213.115.148.64/28
    JA> xl2: Internal: 192.168.20.0/24

    JA> Now my problem seems to be that I need to get external connection for my
    JA> Internal network but not nating the DMZ

    JA> To simplify it all /etc/natd.conf has this line:
    JA> interface xl0

    JA> and to get nat to work I just use:
    JA> ipfw add divert natd log all from any to any via xl0

    JA> but that would nat all the traffic, how should I do just to use nat for
    JA> my 192.168.20.0/24 network and not the 213.115.148.64/28 network?

    JA> /John
    JA> _______________________________________________
    JA> freebsd-net@freebsd.org mailing list
    JA> http://lists.freebsd.org/mailman/listinfo/freebsd-net
    JA> To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"

    -- 
    Best regards,
    ;  Nickolay A. Kritsky
    ; SysAdmin STAR Software LLC
    ; mailto:nkritsky@star-sw.com
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: KC Somaratne: "HP NC7170 Dual Port PCI-X 1000T Gigabit Server Adapter"

    Relevant Pages

    • Re: IPFW + NATD
      ... Network 10,1,0,0/16 does not have external access. ... > As I configure in ipfw using natd to make nat only for net 10.2.0.0/16. ...
      (freebsd-questions)
    • Re: XP Home: selective folder sharing
      ... >same would hold for any wireless connection. ... Explaining bridges vs NAT is not easy. ... network are visible to all other components on each network. ... With a bridge (if Falcon-II is providing one), ...
      (microsoft.public.windowsxp.network_web)
    • Re: XP Home: selective folder sharing
      ... > Explaining bridges vs NAT is not easy. ... > network are visible to all other components on each network. ... > With a bridge (if Falcon-II is providing one), ... > For protection inside the NAT router, ...
      (microsoft.public.windowsxp.network_web)
    • Re: [9fans] Do we have a catalog of 9P servers?
      ... I believe state information and communication buffers are the biggest memory spending for network operations. ... There _could_ be a trade-off between the transient NAT with its processing power toll and the persistent /net-import with its memory cost. ... By contrast, on a large network /net-import strategy could make a "powerful" gateway unavoidable because every machine on the network will need a session with the gateway even if it only rarely communicates with the outside world, unless you implement an ... Or is it because Plan 9 has much less inertia because of a smaller user base? ...
      (comp.os.plan9)
    • Re: [9fans] Do we have a catalog of 9P servers?
      ... network layer data units, ergo, NAT again. ... The "packet ...
      (comp.os.plan9)