Kernel NAT issues

Ian Smith smithi at nimnet.asn.au
Wed Nov 18 16:46:34 UTC 2015


On Wed, 18 Nov 2015 22:17:29 +0800, Julian Elischer wrote:
 > On 11/18/15 8:40 AM, Nathan Aherne wrote:
 > > For some reason hairpin (loopback nat or nat reflection) does not seem to
 > > be working, which is why I chose IPFW in the first place.

 > it would be good to see a diagram of what this actually means.

Anything like ?
http://kb.juniper.net/InfoCenter/index?page=content&id=KB24639&actp=search

Was this so one jail can only access service/s provided by other jail/s, 
both/all with internal NAT'd addresses, by using only the public address 
and port of the 'router', which IIRC this is a single system with jails?

If so, what sort of routing is setup on both host and jails?

(blindfolded, no idea where I've pinned the donkey's tail :)

cheers, Ian


More information about the freebsd-ipfw mailing list