Override default ICMP (and other protocols) default replies.

Javier Ubillos jav at sics.se
Wed Aug 20 21:20:28 UTC 2008


Hi freebsd-net.
(Sorry for cross posting. This time I think I found the right forum for
my question)

I'm implementing a NAT (1 ip - 1 ip) like router. (it's not actually
NAT, but it's a good analogy for this case).

I have chosen to use pcaplib to pick up the packets. I have an
implementation which picks up the packets, inspects them, rewrites the
destination/source ip-addresses and sends them out on the repective
interface.

The problem I'm facing however is that my interfaces are answering to
e.g. icmp-echo (ping) automatically, and I don't know how to turn this
behaviour off.

What I want to happen is that if A pings C, my router B in between
should simply forward the packets w/o any automatic reactions.

A --> B --> C

So that if e.g. C is down, no echo-reply is sent back (or if C is up,
that C is actually sending the echo-reply.

Does any one know how to turn off the automatic replies (ICMP and
whatever else I haven't forseen yet) or does any one know where I can
find out more about the issue?

Thank you // Javier
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.freebsd.org/pipermail/freebsd-net/attachments/20080820/3e43cc2c/attachment.pgp


More information about the freebsd-net mailing list