Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Max Laier
On Monday 22 September 2008 12:22:09 Pawel Jakub Dawidek wrote: > On Fri, Sep 19, 2008 at 03:38:02PM +0200, Max Laier wrote: > > I might be wrong, but I don't think we ever supported rdr without > > net.inet.ip.forwarding enabled. Maybe to a different local address, but > > even then you'd need ne

Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Julian Elischer
Pawel Jakub Dawidek wrote: And what about ipfw variant? For the first (bridge) case ipfw didn't work at all. No packets were redirected. I haven't tried for the gateway case, because pf works there. ipfw forwarding is disabled for bridge and L2 cases. (I think the man page says so.) At Iro

Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Pawel Jakub Dawidek
On Mon, Sep 22, 2008 at 06:11:35PM +0400, Roman Kurakin wrote: > Pawel Jakub Dawidek wrote: > >On Mon, Sep 22, 2008 at 05:31:08PM +0400, Roman Kurakin wrote: > > > >>So, could you draw you connections and related firewall rules. And the > >>one you > >>are trying to setup. I will also try to upd

Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Roman Kurakin
Pawel Jakub Dawidek wrote: On Mon, Sep 22, 2008 at 05:31:08PM +0400, Roman Kurakin wrote: So, could you draw you connections and related firewall rules. And the one you are trying to setup. I will also try to update the machine to the most recent 7 to see if my setup will stop working. Curre

Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Pawel Jakub Dawidek
On Mon, Sep 22, 2008 at 05:31:08PM +0400, Roman Kurakin wrote: > So, could you draw you connections and related firewall rules. And the > one you > are trying to setup. I will also try to update the machine to the most > recent 7 to > see if my setup will stop working. Currently machine runs earl

Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Roman Kurakin
Hi, Pawel Jakub Dawidek wrote: On Fri, Sep 19, 2008 at 03:38:02PM +0200, Max Laier wrote: I might be wrong, but I don't think we ever supported rdr without net.inet.ip.forwarding enabled. Maybe to a different local address, but even then you'd need net.inet.ip.check_interface=0. Looking a

Re: Firewall redirect doesn't work any more...

2008-09-22 Thread Pawel Jakub Dawidek
On Fri, Sep 19, 2008 at 03:38:02PM +0200, Max Laier wrote: > I might be wrong, but I don't think we ever supported rdr without > net.inet.ip.forwarding enabled. Maybe to a different local address, but even > then you'd need net.inet.ip.check_interface=0. Looking at the code, I don't > see wher

Re: Firewall redirect doesn't work any more...

2008-09-21 Thread Roman Kurakin
Pawel Jakub Dawidek wrote: ...or am I missing something? I've a box running: FreeBSD whiplash.wheel.pl 7.0-STABLE FreeBSD 7.0-STABLE #0: Wed Jul 23 11:41:31 CEST 2008 [EMAIL PROTECTED]:/usr/obj/usr/src/sys/WHIPLASH i386 I'm also running PF in there with the following rule: rdr on fxp0 proto

Re: Firewall redirect doesn't work any more...

2008-09-19 Thread Max Laier
On Friday 19 September 2008 14:16:02 Pawel Jakub Dawidek wrote: > On Fri, Sep 19, 2008 at 09:56:33AM +0200, Pawel Jakub Dawidek wrote: > > ...or am I missing something? > > > > I've a box running: > > > > FreeBSD whiplash.wheel.pl 7.0-STABLE FreeBSD 7.0-STABLE #0: Wed Jul 23 > > 11:41:31 CEST 2008

Re: Firewall redirect doesn't work any more...

2008-09-19 Thread Pawel Jakub Dawidek
On Fri, Sep 19, 2008 at 09:56:33AM +0200, Pawel Jakub Dawidek wrote: > ...or am I missing something? > > I've a box running: > > FreeBSD whiplash.wheel.pl 7.0-STABLE FreeBSD 7.0-STABLE #0: Wed Jul 23 > 11:41:31 CEST 2008 [EMAIL PROTECTED]:/usr/obj/usr/src/sys/WHIPLASH i386 > > I'm also running