Re: clarification of NAT behavior

2006-04-07 Thread Karl O. Pinc
On 04/07/2006 11:04:23 AM, Gabriel Wachman wrote: If NAT translation happens BEFORE any filter rules are evaluated (see http://www.openbsd.org/faq/pf/nat.html), then wouldn't it be true that an outbound packet from the internal network will be seen by the filtering engine as a packet with source

clarification of NAT behavior

2006-04-07 Thread Gabriel Wachman
I posted this on misc@openbsd.org, but realized maybe I would have better luck posting here. What follows is my original post plus the one reply I received and my subsequent response. On Sat, Apr 01, 2006 at 03:28:36PM -0500, Gabriel Wachman wrote: Everything I know about PF is taken from the