Re: NAT - PF order

2003-09-15 Thread Trevor Talbot
On Sunday, Sep 14, 2003, at 17:55 US/Pacific, Shadi Abou-Zahra wrote: (all the following NICs are in a single bridge) NIC_A: IP 123.123.0.1, connected to the big bad internet NIC_B: IP 192.168.0.1, internal network (desktops etc) NIC_C: IP 10.0.0.1, internal servers (development and staging area)

RE: NAT - PF order

2003-09-14 Thread Shadi Abou-Zahra
> > hopefully this is not a millionth repetition of a subject but after > > reading the PF FAQ and some of the mail archives i am still > > confused about how bridging, NATing and PFing all work together. > > the exact path of the packets through the NICs is still a little > >unclear to me. may

Re: NAT - PF order

2003-09-12 Thread Trevor Talbot
On Thursday, Sep 11, 2003, at 15:52 US/Pacific, Shadi Abou-Zahra wrote: hopefully this is not a millionth repetition of a subject but after reading the PF FAQ and some of the mail archives i am still confused about how bridging, NATing and PFing all work together. the exact path of the packets

RE: NAT - PF order

2003-09-12 Thread Shadi Abou-Zahra
hi, just a reminder: NIC_A: IP 123.123.0.1, connected to the big bad internet NIC_B: IP 192.168.0.1, internal network (desktops etc) NIC_C: IP 10.0.0.1, internal servers (development and staging area) NIC_D: NO IP, DMZ 1 (a collection of operational www and mail servers) NIC_E: NO IP, DMZ 2 (a col

Re: NAT - PF order

2003-09-12 Thread Stefan Zill
Shadi Abou-Zahra wrote: > hello, Hi, > here are my questions: > 1. NATing always happens before PF rules are applied. correct? This is correct. > 2. if all the NATing happens on NIC_A, why do i get such entries in my > state table when an internal desktop tries to reach a server in DMZ 1: > 192