1. J

    PF pf rule to NAT all interfaces except en0 and en1

    Situation: VPN server, hosting OpenVPN and L2TP connections. OpenVPN connections share a "utun" interface, one per OpenVPN server process. L2TP connections each get a unique "ppp" interface. Given the variable number & names of virtual interfaces, the easiest way to capture all of the potential...
  2. repcsi

    PF Update from 12.2-RELEASE-p11 to 12.3-RELEASE-p7 broke my PF internet router/firewall

    Hi all, I updated my internet facing router/firewall from 12.2-RELEASE-p11 to the latest 12.3 release: 12.3-RELEASE-p7. I'm using a custom kernel with ALTQ support as it helps with my transfer speeds. More info on this below as I even disabled ALTQ to try to solve this issue. The issue: after...
  3. T

    IPFW IPFW server, acting as a firewall (how to pass traffic ?)

    Hello everyone, Experimenting IPFW, I would really appreciate some help to improve my abilities ! I actually know how to use it as a workstation firewall, but now, I would like to learn how to use it as an easy full firewall (just for experimenting). Here is an easy network map describing what...
  4. maxmrkwrt

    PF Allow incoming packets on a port used for NAT

    I would like to pass incoming packets on a specific port, which is used for NAT, even if these packets don't match a connection from the NAT table. I use a machine with FreeBSD and pf as a router. A PBX on my local network must both reach a phone provider on the internet and be reachable...
  5. HL1234

    Get my NAT IPFW firewall for jail not to work from outside

    Hello, in short: A Jail is installed. Can start and stop and connect to it. Inside its running an Apache web server. Some simple Website exists. Starting the jail and make a test like this works: printf "HEAD / HTTP/1.1\r\nHost: <>t\r\n\r\n" also telnet <> 80...
  6. Rudy

    Solved NAT + IPSEC ... can't get it to work

    At an office, a FreeBSD router is set up using ipfw and nat. This part works great and has for years. We added an ipsec tunnel for a remote network. I have the tunnel up, and can ping from the internal interface (em1 to the remote IP, no problem. For the nat, I set up...
  7. DrAngel

    Solved FreeBSD+OpenVPN+nat/fwd = not forward for WWW-server

    Good day everyone! Can't beat the following problem. Internet -> router (x.x.x.x/ -> ASC server {FreeBSD12+ipfw/nat/fwd (|If_Inet) + OpenVPN server (|If_VPN)} -> ADM server {OpenVPN client (|If_VPN) + FreeBSD12 www-server (Ip_WWW)} ->...
  8. Sivan!

    Is there a way to "mask" a DHCP assigned IP address in a personal computer?

    I do not have a static IP for my computer connected by fiber to home. My ISP assigns an IP address by DHCP, is there a way of making my ISP's router at my home remember the address assigned to me by local settings? I do not fully understand but this URL to a how-to guide points to a method...
  9. F

    Solved OpenVPN + NAT + routing

    Hi, everyone. Seems like between the times I DO the PF config, I forget something very important :) Anyway. My box has 3 NICs. There is WAN and LAN ethernets, then there is a WIFI AP managed by hostapd. And here is my /etc/pf.conf: out_if = "igb0" lan_if = "igb1" wifi_if = "wlan0" nonroute =...
  10. G

    Solved Bridging dissimilar networks/NAT configuration

    I am attempting to create a virtual network on VMware using FreeBSD as a router and a firewall. I am relatively new to many of the concepts involved here. I have FreeBSD currently setup as a DHCP server on my vlan(I will eventually switch to static networking), it is issuing addresses on a...
  11. T

    PF Jail pinging host public ip but not able to access the cloud - VNET

    I have an issue forwarding the packets to the cloud from the jail. I have tested Netgraph and epair with the same result. I have enabled nat in sysctl.conf>> net.inet.ip.forwarding=1 I have disabled PF totally and tried with nat enabled nat on $ext_if inet from $jail_if to any -> ($ext_if) In...
  12. alfa

    FreeBSD IPsec enc0 NAT not works this is the problem

    Hi, i have trouble with Ipsec & pf enc0 nat problem . I show you my problematic scenerio below any help would be appreciated at this point STRONGSWAN CONFIGURATION alfa7000 { fragmentation = yes unique = replace version = 1 aggressive = no proposals...
  13. I

    is it possible to port forward using ppp nat ??

    Hello everyone ! I need to port forward 3074 from destination external device (tun0) to internal device which (em0) but I need it using ppp nat. I enabled ppp nat in rc.conf and it masquerade tun0 device from internal device now I need to port forward I tried with PF but it gives me strict nat...
  14. S

    PF [Still Unsolved] Redirect port from VPS to home server without using NAT

    HTTP(S) is just an example, I have many other services that wouldn't be able to communicate the real IP via a proxy, therefore PF solution is a must. I am referring to RDR and NAT as they are understood in the context of pf.conf (i.e. I mean the RDR and NAT statements). Both my VPS and Home...
  15. U

    Solved Passing all outbound trafic from Jail behind NAT

    I'm trying to pass all outbound traffic from Jails. I'm using IPFW, because it's default for FreeBSD. All Jails live on cloned lo1 interface, no VNET. How can I pass all outbound traffic from my Jails to the Internet through vtnet0 interface? PLEASE DELETE THIS THREAD.
  16. RevennaFox

    PBX Server Guru Help Needed

    I guess I should probably start by explaining what I'm trying to do. I have a pair of Grandstream HandyTone analog telephone adapters that I need to work with incoming and outgoing calls to a SIP trunking provider over Asterisk running on a remote FreeBSD server. The ATAs are behind NAT, the...
  17. I

    How to configure FreeBSD PC to Mac using an Ethernet crossover cable to access the Internet?

    I have: a router - with an internal IP address and is connected to the Internet. a Mac - has the IP address of Internet works, of course. a PC with FreeBSD 13 installed. I have connected the FreeBSD PC to the Mac using an Ethernet crossover cable. I have assigned...
  18. M

    PF Nat is not forwarding to jail

    I am using PF and cannot get packets forwarded to a particular jail. I want data that comes into my base machine on port 4243 to be forwarded to my jail that has a service that is listening on port 4243. I have verified with telnet that the jail can receive data on that port. Here is my...
  19. T

    Connection Tracker sources

    Hi, I'd wish to read and understand the source code used for tracking connection and feeding NAT. May someone point me to the right place in the source tree? Thanks, Claudio
  20. T

    Solved Update IPv6 routes on a gateway from upstream router advertisements?

    I'm running an AP that bridges traffic to my ISP. For various reasons, I'm running both IPv4 and IPv6 and I need to NAT traffic from the LAN to the ISP. For this reason, net.inet6.ip6.forwarding needs to be enabled. The usual solution for periodically updating the IPv6 gateway address seems to...