Re: Hiding NATs with PF

From: Max Bolingbroke (batterseapower_at_hotmail.com)
Date: 09/29/05


Date: 29 Sep 2005 02:51:36 -0700

Simon Farnsworth wrote:
> You need a block rule to get PF to avoid it. Given a table <private> with
> all RFC 1918 addresses in it:
>
> block quick on $ext_if from <private> to any

Thats a great help. However, at the moment I am testing the NAT by
having it nested within another NAT, so enabling this rule would block
the external interface from sending/recieving any packets since it
itself has an address in the 192.168.1.x range. I remedied this by
using a rule like:

block drop out quick on $ext_if from 192.168.2.0/24 to any

Where the NATed network managed by OpenBSD has addresses in the range
192.168.2.x. This should be OK, right?

> This stops your machine sourcing private addresses, and "all" you need to do
> is make sure that the cables *never* get swapped; if your internal
> interface is connected to the campus network, you run the risk of big
> trouble.

Mmm.. poisoning routing information would be the least of my worries
given that I'd be handing out dhcp leases to all and sundry.

Thanks for your help,

Max



Relevant Pages

  • Re: ISA dial up issue
    ... external interface of the ISA box... ... if there are access rules on the ISA allowing traffic ... case just hit the external IP) there is no NAT or proxying. ...
    (microsoft.public.isa)
  • Problem Receiving Internet E-Mails On ISA/Exchange Server
    ... of the NAT Device. ... NAT device to the external interface of the ISA server. ... >public IP and a private IP. ...
    (microsoft.public.isa.configuration)
  • Re: [fw-wiz] Site to siteVPN between public ip and private ip
    ... Behalf Of Ratna Thurairatnam ... it's external interface? ... At your end use "NAT Traversal". ... At the other end either use the public IP of the landlord network or use ...
    (Firewall-Wizards)
  • Order of NAT, ACL, VPN etc in IOS
    ... I found out the hard way that static NAT stops the VPNs working, ... Also ACLs applied inbound on the external interface use ...
    (comp.dcom.sys.cisco)
  • Re: nochmal Vista FW
    ... Sicherheitsgewinne ... NAT bietet ... Security Considerations ... Abschnitt '4.0. Various flavors of NAT' in RFC 2663 bzw. ...
    (de.comp.security.misc)