NAT with IP != primary external IP

Aled Treharne aled at thinknuts.org
Sat Oct 23 04:16:13 PDT 2004


Hi guys.

I'm trying to set up a firewall on a box for a friend. The arrangement is
fairly simple, bunch of machines behind the FBSD box, FBSD box connected to
ADSL. What I'd like to do (because I wanted to in the first place, and now
it's annoying me) is to have 2 Ips on the external i/f on the FBSD box, and
have one as the machine's primary IP and t'other solely as the NAT IP. I've
tried putting various Ips in the places that make sense to me, but I just
couldn't get it to work[1].

Is this possible, and if so, would someone be so kind as to tell me how? I'm
trying to move over to pf from ipfw, and if I can get it working, I've got a
strong case for using it at work as well. 

Thanks in advance for your sage advice. :)

Cheers,
Aled.

[1] This is just one place where I prefer linux's eth0:alias1 type labelling
of sub-interfaces over FreeBSD's just-put-multiple-ips-on-one-interface way.




More information about the freebsd-pf mailing list