I have been trying to get this setup to work for a few days.
I have a single WAN interface (bce0) that has a couple of public IPs attached to it. I would like to use one of these IPs for the host (wanip1) and jails and another for a jail (wanip2) that requires a public IP. I have a cloned lo0 interface, lo1 with a subnet of 10.1.0.0/24 which all the jails reside on. I would like to forward ports 80,443 coming in on wanip1 to the jail proxy, which then forwards the traffic off to the correct jail. I would like the jails to be able to have their own firewall setups, which I currently do by including a firewall script writable by each jail. I would also like each jail to be able to connect to the internet.
I have been trying to follow this post here - https://forums.freebsd.org/threads/ipfw-nat-setting.46929/#post-262399 but this post is to do NAT on the interface not the IP. I cannot use the interface as there is another public IP attached to it. I realize that I should be able to make some small changes to the example in this post and get it to work but that doesn't seem to be the case. I got it to work when I followed exactly but it stopped working when I change the references from <wan interface> to <wan ip> (where I could).
I have a single WAN interface (bce0) that has a couple of public IPs attached to it. I would like to use one of these IPs for the host (wanip1) and jails and another for a jail (wanip2) that requires a public IP. I have a cloned lo0 interface, lo1 with a subnet of 10.1.0.0/24 which all the jails reside on. I would like to forward ports 80,443 coming in on wanip1 to the jail proxy, which then forwards the traffic off to the correct jail. I would like the jails to be able to have their own firewall setups, which I currently do by including a firewall script writable by each jail. I would also like each jail to be able to connect to the internet.
I have been trying to follow this post here - https://forums.freebsd.org/threads/ipfw-nat-setting.46929/#post-262399 but this post is to do NAT on the interface not the IP. I cannot use the interface as there is another public IP attached to it. I realize that I should be able to make some small changes to the example in this post and get it to work but that doesn't seem to be the case. I got it to work when I followed exactly but it stopped working when I change the references from <wan interface> to <wan ip> (where I could).