NAT Questions



I originally posted this to the FreeBSD questions mailing list, but did
not receive any responses. If you are reading this for the second time,
please accept my apologies.

My ISP insists on handing all http traffic off to me on a separate IP
address.

Following is my configuration.

External Interface------->Internal Interface--------> Rest of network
1.2.3.4/24 10.129.10.40/24
1.2.3.5/32 Alias

1.2.3.5/24 is the IP address all http traffic will come in on. 1.2.3.4/32
is the IP address all other traffic will come in on. Both of these
addresses reside on a single NIC with 1.2.3.5 being an alias.

ipnat.rules
rdr 1.2.3.5/32 port 80 -> 10.129.10.49 port 80
map em1 10.129.10.0/24 -> 0.0.0.0/32

10.129.10.49 has 10.129.10.40 (my firewall) listed as its default gateway.
When it responds to a request that has been forwarded, how will the
firewall return the response? Will it return the request on 1.2.3.5?

Thanks for your help and if any additional information is needed, please
let me know.




Jay

_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: NAT Questions
    ... addresses reside on a single NIC with 1.2.3.5 being an alias. ... has 10.129.10.40 (my firewall) listed as its default gateway. ... When it responds to a request that has been forwarded, ... The response will have 1.2.3.5 as source-address, the nat software remember that the translation/mapping was done on 1.2.3.5. ...
    (freebsd-net)
  • Re: Jan II: might be fixed! [WAS: Cant type in IE 6 or OE on Win XP Home PC}
    ... As you do not want me to insert responses I will have to respond here ... that is the HijackThis thread. ... I also don't install random stuff for no reason. ... I also use another software firewall (Conseal PC ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Life as an attorney
    ... THIRD REQUEST FOR PRODUCTION AND BRIEF IN SUPPORT TO THE HONORABLE ... Responses to Defendants’ Third Request for Production. ... Plaintiff has been specifically advised as to the defects in the ...
    (rec.games.chess.politics)
  • A signed root zone and BIND
    ... The root zone is in the process of being signed. ... operators to test whether they can receive signed responses cleanly. ... You can see whether your firewall will pass such responses by running ...
    (comp.protocols.dns.bind)
  • A signed root zone and BIND
    ... The root zone is in the process of being signed. ... operators to test whether they can receive signed responses cleanly. ... You can see whether your firewall will pass such responses by running ...
    (comp.protocols.dns.bind)