[RESOLVED] NAT redirection for jails

Hello,

All the tutorials I found online about the PF firewall involve NAT redirection for the jails. Could someone explain why this is the case as most of the time the jails share the same network interface and the router deals with NAT?

Thank you,
Fred
 
Re: NAT redirection for jails

You would need NAT if you bind your jails to lo1 for example. If you bind your jails to an external interface then NAT would not be needed.
 
Re: NAT redirection for jails

SirDice said:
You would need NAT if you bind your jails to lo1 for example. If you bind your jails to an external interface then NAT would not be needed.

The deciding factor is the "visibility" of the jail IP addresses outside the host that runs the jails. If the jail addresses are directly reachable (if you leave out packet filtering out of the equation) from the connected networks you don't need NAT, otherwise you do need it.
 
Back
Top