misc/116238: natd/ipfw not maintaining interface of udp packets
(maybe tcp too?)
Andrey V. Elsukov
bu7cher at yandex.ru
Mon Sep 10 00:00:17 PDT 2007
The following reply was made to PR misc/116238; it has been noted by GNATS.
From: "Andrey V. Elsukov" <bu7cher at yandex.ru>
To: Joe Acosta <josepha48 at yahoo.com>
Cc: freebsd-gnats-submit at FreeBSD.org
Subject: Re: misc/116238: natd/ipfw not maintaining interface of udp packets
(maybe tcp too?)
Date: Mon, 10 Sep 2007 10:53:53 +0400
Joe Acosta wrote:
>> Description:
> natd is natting everything and messing up certain outgoing packets.
No. natd is natting only packets wich it gets from the divert socket.
You should make *correct* "ipfw divert" rules.
>> How-To-Repeat:
> install dhcp, on a dual nic box.
> setup a firewall and nat on ext nic using ipfw/natd
> try to get dhcp ip address on internal lan
Why you pass DHCP packets into divert socket? Don't do it.
--
WBR, Andrey V. Elsukov
More information about the freebsd-bugs
mailing list