Re: PF & Inside NAT

2011-10-17 Thread Eric Masson
"Bjoern A. Zeeb" writes: Hello Bjoern, > of this, and yes, the pf in FreeBSD still lacks it. Ok. Thanks a lot for the answer. Regards Éric Masson -- ça reste finalement une décision personnelle, sans contraintes externes, puisqu'il n'y a rien à prouver dans ce domaine aux variables exogè

Re: PF & Inside NAT

2011-10-17 Thread Eric Masson
Damien Fleuriot writes: Hi Damien, > I totally did not understand whatever you're trying to say. > En d'autres termes, j'ai rien compris. Pas grave ;) > What do you call "inside nat" ? The ability to trigger nat via incoming packets (useful in a nat before vpn scenario), just like libalias do

PF & Inside NAT

2011-10-17 Thread Eric Masson
Hello, Does the PF 4.5 port present in -current & 9-STABLE support inside NAT please (somewhat like the reverse nat available with libalias) ? Kind Regards Éric Masson -- Je n'ai pas envie de perdre mon temps à leur APD à la con. Mais j'ai besoin du certificat qu'y est délivré, pour passer l

Henning's slide from Venice

2005-11-17 Thread Eric Masson
Hello, Has anyone seen this slide : http://www.openbsd.org/papers/ven05-henning/index.html PF section talks about new features and certain ones such as interface groups are really nifty. Is there any hope to see new features in FreeBSD one of these days or are these changes way too intrusive ?

Re: Filtering IPSec traffic ?

2005-10-25 Thread Eric Masson
VANHULLEBUS Yvan <[EMAIL PROTECTED]> writes: > And the main problem of using gif interfaces seems to be a gif + IPSec > + filtering + forwarding problem for (at least) big TCP sessions (see > the thread on freebsd-net). Just checked, maybe it's a regression, this kind of setup works on a prototyp

Re: Filtering IPSec traffic ?

2005-10-25 Thread Eric Masson
VANHULLEBUS Yvan <[EMAIL PROTECTED]> writes: Hi Yvan, > That's the problem: enc0 doesn't seems to exists, at least on my > FreeBSD6 gate (perhaps I missed something in the configuration, or > perhaps this is not a "real" interface ?) !!! The enc(4) interface doesn't exist in FreeBSD. Atm, I use

Re: Pf in 4.11

2005-05-12 Thread Eric Masson
Christopher McGee <[EMAIL PROTECTED]> writes: Hi, > The handbook states that pf is available through KAME in 4.11 and from > my reading Kame is build into the system. How do you enable pf and altq > on 4.x then. I have had trouble finding any how-to's on this since > everything for pf points to