NOTE:
My ipfilter version is 3.4.5
My OS: FreeBSD 4.0-Release
ipnat.conf is my ipnat rules file
Problem:
1.The packet from 10.0.0.0/8 to 210.74.134.16/28 still be translaed.
rule:map fxp2 from 10.0.0.0/8 to 210.74.134.16/28 -> 0/0
result:MAP 10.131.113.30 1312 <- -> 210.74.134.24 10003
[210.74.134.18 53]
2.the option "round-robin" doesn't work as before.
rules:rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.2 port 8080 round-robin
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.3 port 8080 round-robin
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.4 port 8080 round-robin
result:(below)
----------------------------------------------------------------------------
------------------
# more ipnat.conf
map fxp2 from 10.0.0.0/8 to 210.74.134.16/28 -> 0/0
map fxp2 10.0.0.0/8 -> 210.74.134.24/32 portmap tcp/udp 10000:20001
map fxp2 10.0.0.0/8 -> 210.74.134.24/32
rdr fxp1 210.74.134.21/32 port 0 -> 210.74.134.21 port 0
rdr fxp1 210.74.134.22/32 port 0 -> 210.74.134.22 port 0
rdr fxp1 210.74.134.23/32 port 0 -> 210.74.134.23 port 0
rdr fxp1 210.74.134.25/32 port 0 -> 210.74.134.25 port 0
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.2 port 8080 round-robin
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.3 port 8080 round-robin
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.4 port 8080 round-robin
# ipnat -l
List of active MAP/Redirect filters:
map fxp2 from 10.0.0.0/8 to 210.74.134.16/28 -> 0.0.0.0/0
map fxp2 10.0.0.0/8 -> 210.74.134.24/32 portmap tcp/udp 10000:20001
map fxp2 10.0.0.0/8 -> 210.74.134.24/32
rdr fxp1 210.74.134.21/32 -> 210.74.134.21 tcp
rdr fxp1 210.74.134.22/32 -> 210.74.134.22 tcp
rdr fxp1 210.74.134.23/32 -> 210.74.134.23 tcp
rdr fxp1 210.74.134.25/32 -> 210.74.134.25 tcp
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.2 port 8080
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.3 port 8080
rdr fxp1 0.0.0.0/0 port 80 -> 192.168.16.4 port 8080
List of active sessions:
RDR 192.168.16.2 8080 <- -> 195.97.242.240 80 [10.131.113.30 1313]
MAP 10.131.113.30 1312 <- -> 210.74.134.24 10003 [210.74.134.18 53]
RDR 192.168.16.2 8080 <- -> 63.84.122.206 80 [10.131.113.30 1311]
RDR 192.168.16.2 8080 <- -> 63.236.73.251 80 [10.131.113.30 1310]
MAP 10.131.113.30 1309 <- -> 210.74.134.24 10002 [210.74.134.18 53]
RDR 192.168.16.2 8080 <- -> 63.84.122.206 80 [10.131.113.30 1308]
RDR 192.168.16.2 8080 <- -> 63.84.122.206 80 [10.131.113.30 1307]
RDR 192.168.16.2 8080 <- -> 216.35.211.246 80 [10.131.113.30 1306]
MAP 10.131.113.30 1305 <- -> 210.74.134.24 10001 [210.74.134.18 53]
RDR 192.168.16.2 8080 <- -> 63.84.122.206 80 [10.131.113.30 1304]
RDR 192.168.16.2 8080 <- -> 63.84.122.206 80 [10.131.113.30 1302]
MAP 10.131.113.30 1301 <- -> 210.74.134.24 10000 [210.74.134.18 53]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1297]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1296]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1295]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1294]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1292]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1291]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1290]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1288]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1287]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1286]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1285]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1284]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1283]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1282]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1281]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1280]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1279]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1278]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1277]
RDR 192.168.16.2 8080 <- -> 195.62.38.251 80 [10.131.113.30 1276]
#
___________________________________
UPDATED Posting Guidelines: http://www.groupstudy.com/list/guide.html
FAQ, list archives, and subscription info: http://www.groupstudy.com
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]