Issue with routing table entries, jails and pf filtering on loopback interfaces

2015-06-19 Thread Thomas Steen Rasmussen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello list, This will be a long post, apologies, but it is a complex issue. First I will explain how the server is configured, then I will explain the problem and the workaround I found. When I add one or more IP aliases to a non-loopback interface

Large scale NAT with PF - some weird problem

2015-06-19 Thread Milan Obuch
Hi, I am managing FreeBSD 9 based router for a network using PF for NAT. I think I can call it large scale - there is approximately 3000 customers' devices (home routers and similar) with private IPs in segment 172.16.0.0/12 translated to /23 public address block. Basically, in pf.conf, there is

[Differential] [Commented On] D1944: PF and VIMAGE fixes

2015-06-19 Thread robak (Bartek Rutkowski)
robak added a comment. Is there any chance to get these changes committed in time for 10.2-RELEASE? It would be great if we could have working VNET/PF before 11.0-R comes out... REVISION DETAIL https://reviews.freebsd.org/D1944 EMAIL PREFERENCES https://reviews.freebsd.org/settings/panel/e

Re: adding an additional block & gateway

2015-06-19 Thread Kajetan Staszkiewicz
Dnia piÄ…tek, 19 czerwca 2015 00:10:01 Chuck @ Mantis pisze: > I'm currently using FreeBSD and PF as a gateway and firewall in front of > a handful of web servers. > > External: > defaultrouter="79.112.227.33" > ifconfig_bge0="inet 79.112.227.34 netmask 255.255.255.224" > > I've asked the datacent

Re: adding an additional block & gateway

2015-06-19 Thread Chuck @ Mantis
Our data center responded to your question, here is the text: We can confirm that the new netblock is routed direct via your vlan as with your original netblock VLAN: vlan655-cbcbmedi-809, Created at: Mon Oct 20 13:42:05 2014 802.1Q Tag: 655, Internal index: 205, Admin State: Enabled, Origin: S