Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Binat with exceptions
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  2 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Falk Husemann  
View profile  
 More options Jul 5, 1:41 am
Newsgroups: bit.listserv.openbsd-pf
From: jo...@paketsequenz.de (Falk Husemann)
Date: 4 Jul 2009 08:41:45 -0700
Local: Sun, Jul 5 2009 1:41 am
Subject: Binat with exceptions
Hello all on the pf list,

for a really stupid german ISP I need to setup a binat with  
exceptions. Here is my current setup:

(Internet) -- (cable modem) -- [dhcp] (openbsd-router) [10.10.0.1] --  
[dhcp, 10.10.0.2] -- (Fritz!Box)

and

(openbsd-router) [172.16.1.1] -- [172.16.1.20] (Linux-Server)

What I want to do is redirect everything on every port from external  
ip of openbsd-router to the Fritz!Box on 10.10.0.1, the "Fritz!Box  
quarantine network".
Then I want to redirect a handful of port that are unused by the Fritz!
Box to internal machines on my private net.
And also I want to do nat for the internal private net 172.16.1.0/24.  
The usual stuff.

My solution would be to rdr pass all ports between the handful I want  
to forward to my private net to the Fritz!Box. That would probably  
work as expected, but I thought that binat could be a useful solution  
for not having 65.000 seperate rules (which would suck on an Alix  
board).

How would it work? I guess with the no keyword, but a small working  
example (copy&paste your working pf-rules without private data) would  
help a lot. I already found this thread from September 2008:

http://groups.google.com/group/bit.listserv.openbsd-pf/browse_thread/...

Would Martins example for for my case if ext_ip1 and ext_ip2 were the  
same?

Thanks in advance for any suggestions.

Falk


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Karl O. Pinc  
View profile  
 More options Jul 5, 2:11 am
Newsgroups: bit.listserv.openbsd-pf
From: k...@meme.com (Karl O. Pinc)
Date: 4 Jul 2009 09:11:38 -0700
Local: Sun, Jul 5 2009 2:11 am
Subject: Re: Binat with exceptions

On 07/04/2009 04:59:21 AM, Falk Husemann wrote:

> Hello all on the pf list,

> for a really stupid german ISP I need to setup a binat with  
> exceptions.
> Thanks in advance for any suggestions.

You could take advantage of the fact that the first
matching translation rule ends the processing,
so put your exceptions first and then a general
catch-all.

Don't forget that because binats are processed
before nats and rdrs a binat rule will cause
ftp-proxy anchors to be ignored.  So use a nat together with an rdr
instead of binat for those ports that ftp-proxy
might use.

Karl <k...@meme.com>
Free Software:  "You don't pay back, you pay forward."
                  -- Robert A. Heinlein


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google