Re: keep-state and in-kernel NAT exposes local ip on external interface

2015-07-29 Thread Julian Elischer
On 7/29/15 3:43 AM, Lev Serebryakov wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 28.07.2015 08:30, Ian Smith wrote: I have global lack of any spare time (and all my FreeBSD activity is only a hobby) for last ~2 months. I see the end of this unfortunate state of affairs in near fu

Re: keep-state and in-kernel NAT exposes local ip on external interface

2015-07-29 Thread bycn82
*Hi Julian,* *So below are the rules in your example* *5 skipto 10 from A to B* *6 skipto 11 from any to any* *10{action} from A to B keep-state* *11{action} from C to D* *If I remove the "skipto" rules they will become* *10 {action} from A to B keep-state* *11 {action} from C to D * *Correc

Re: keep-state and in-kernel NAT exposes local ip on external interface

2015-07-29 Thread Julian Elischer
On 7/29/15 5:26 PM, bycn82 wrote: /Hi Julian,/ / / /So below are the rules in your example/ / / /5 skipto 10 from A to B / /6 skipto 11 from any to any/ /10{action} from A to B keep-state/ /11{action} from C to D/ / / / / /If I remove the "skipto" rules they will become/ // /10 {action} from A to

Re: keep-state and in-kernel NAT exposes local ip on external interface

2015-07-29 Thread bycn82
*Hi,* *But I dont understand why you said C->D is already in the dynamic table? which line create the dynamic rule for it?* *Regards,* *bycn82* On 29 July 2015 at 22:03, Julian Elischer wrote: > On 7/29/15 5:26 PM, bycn82 wrote: > > *Hi Julian,* > > *So below are the rules in your example*

Re: keep-state and in-kernel NAT exposes local ip on external interface

2015-07-29 Thread Julian Elischer
On 7/29/15 10:23 PM, bycn82 wrote: /Hi,/ /But I dont understand why you said C->D is already in the dynamic table? which line create the dynamic rule for it?/ /it happened on a previous packet at some other rule, for example 30 allow ip from any to D 80 keep-state / / / /Regards,/ /bycn82

Re: keep-state and in-kernel NAT exposes local ip on external interface

2015-07-29 Thread Julian Elischer
On 7/30/15 3:34 AM, Julian Elischer wrote: On 7/29/15 10:23 PM, bycn82 wrote: /Hi,/ /But I dont understand why you said C->D is already in the dynamic table? which line create the dynamic rule for it?/ /it happened on a previous packet at some other rule, for example 30 allow ip from any to