question on NAT for multiple subnets

Greg Barniskis gregb at
Fri Feb 17 08:42:56 PST 2006

I'm sure I could figure this out from scrutinizing Google, the 
FreeBSD documentation, and testing in a lab, but I'm particularly 
pressed for time on finding the right answer to this.

For a long time we've been quite happy coalescing all private IP 
client requests onto a single public IP address through NAT. 
Management now wants more granularity, at least one unique public IP 
per private subnet.

Can I set up a single ipfw box that examines client source ip addrs 
and provides different public NAT addrs for each private client subnet?

Any pointers to the best way to think about this issue much 
appreciated. If the answer is ipfw doesn't handle this, but some 
other fw does, fine, I just need to know which. Thanks!

Greg Barniskis, Computer Systems Integrator
South Central Library System (SCLS)
Library Interchange Network (LINK)
<gregb at>, (608) 266-6348

