problem with ipfilter(ipnat)

fbsd fbsd at
Wed Apr 12 12:32:37 UTC 2006

There is nothing wrong with FreeBSD 6.0
It's the way you activated ipf that is wrong.
Ipfilter's ipnat function is not an independent function.
You have to code this in rc.conf
ipfilter_enable = "YES"
ipnat_enable = "YES"

and make sure there is no default ipf.rules file

Then ipf will use its default pass all rule which results in the
ipnat function working with a firewall rule of pass all

Also your nat rules are incorrect.
The special alias should be 0/32

The FreeBSD handbook has a good section on ipfilter.

-----Original Message-----
From: owner-freebsd-questions at
[mailto:owner-freebsd-questions at]On Behalf Of Arnold Lee
Sent: Wednesday, April 12, 2006 4:34 AM
To: freebsd-questions at
Subject: problem with ipfilter(ipnat)

  I am in a small lan and want to use fb 6.0 as a router to share
internet access. I use mpd 3.18 to dial adsl on demand. I configured
ipnat with :
   map rl0 -> portmap tcp/udp auto
 map rl0 ->
And then I use my client compute(windows 2000 Pro) to access
internet, it seems ok, but soon I realize that there are some
websites I can not access! For example, is
unacessable! So are some ftp sites such as It must
be a problem of the FB6 box, because if i access internet directly
from the win2000 box, all those sites above is ok ! what is wrong?
By the way, I donot use ipfirewall and other firewall, and in
rc.conf, I wrote "ipfilter_enable = NO, ipnat_enable= YES". Can you
help me?

freebsd-questions at mailing list
To unsubscribe, send any mail to
"freebsd-questions-unsubscribe at"

More information about the freebsd-questions mailing list