<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: NAT в ядре синтаксис?</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID1/82253.html</link>
    <description>Народ, кто нить разберался с синтаксисом NAT в ядре фри 7 (option FIREWALL_NAT)&lt;br&gt;как правильно записать нат для двух интерфейcов rl1 и rl0, надо чтоб rl1(LAN) маскировался rl0(INTERNET)&lt;br&gt;</description>

<item>
    <title>NAT в ядре синтаксис? (alex123)</title>
    <link>https://www.opennet.ru/openforum/vsluhforumID1/82253.html#1</link>
    <pubDate>Fri, 03 Oct 2008 13:04:20 GMT</pubDate>
    <description> Вот что нашёл по етому поводу:&lt;br&gt;&lt;br&gt;   NAT, REDIRECT AND LSNAT&lt;br&gt;     First redirect all the traffic to nat instance 123:&lt;br&gt;&lt;br&gt;   ipfw add nat 123 all from any to any&lt;br&gt;&lt;br&gt;     Then to configure nat instance 123 to alias all the outgoing traffic with&lt;br&gt;     ip 192.168.0.123, blocking all incoming connections, trying to keep same&lt;br&gt;     ports on both sides, clearing aliasing table on address change and keep-&lt;br&gt;     ing a log of traffic/link statistics:&lt;br&gt;&lt;br&gt;   ipfw nat 123 config ip 192.168.0.123 log deny_in reset same_ports&lt;br&gt;&lt;br&gt;     Or to change address of instance 123, aliasing table will be cleared (see&lt;br&gt;     reset option):&lt;br&gt;&lt;br&gt;   ipfw nat 123 config ip 10.0.0.1&lt;br&gt;&lt;br&gt;     To see configuration of nat instance 123:&lt;br&gt;&lt;br&gt;   ipfw nat 123 show config&lt;br&gt;&lt;br&gt;     To show logs of all the instances in range 111-999:&lt;br&gt;&lt;br&gt;   ipfw nat 111-999 show&lt;br&gt;&lt;br&gt;     To see configurations of all instances:&lt;br&gt;&lt;br&gt;   ipfw nat show config&lt;br&gt;&lt;br&gt;     Or a redirect rule with mixed modes could looks like:&lt;br&gt;&lt;br&gt;   ipfw nat 123 config redirect_addr 10.0.0.1 10</description>
</item>

</channel>
</rss>
