diff options
author | rpaulo <rpaulo@FreeBSD.org> | 2012-06-28 03:30:17 +0000 |
---|---|---|
committer | rpaulo <rpaulo@FreeBSD.org> | 2012-06-28 03:30:17 +0000 |
commit | 9acfdeb85517cbad2f81c3cd563451edfbdd9b24 (patch) | |
tree | a0b021a2fc1d3248f58cbdb3b2d6a1c841e52a54 /share/examples | |
parent | 42cfd3d28dbb736d2aec3a010a9f5caeee3fd03e (diff) | |
download | FreeBSD-src-9acfdeb85517cbad2f81c3cd563451edfbdd9b24.zip FreeBSD-src-9acfdeb85517cbad2f81c3cd563451edfbdd9b24.tar.gz |
Add the 'inet' keyword after the nat rule to avoid interfering with
IPv6.
Diffstat (limited to 'share/examples')
-rw-r--r-- | share/examples/pf/faq-example1 | 2 | ||||
-rw-r--r-- | share/examples/pf/pf.conf | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/share/examples/pf/faq-example1 b/share/examples/pf/faq-example1 index 91942f6..e9b240f 100644 --- a/share/examples/pf/faq-example1 +++ b/share/examples/pf/faq-example1 @@ -26,7 +26,7 @@ set skip on lo scrub in # nat/rdr -nat on $ext_if from !($ext_if) -> ($ext_if:0) +nat on $ext_if inet from !($ext_if) -> ($ext_if:0) nat-anchor "ftp-proxy/*" rdr-anchor "ftp-proxy/*" diff --git a/share/examples/pf/pf.conf b/share/examples/pf/pf.conf index 299999d..d97b4ed 100644 --- a/share/examples/pf/pf.conf +++ b/share/examples/pf/pf.conf @@ -16,7 +16,7 @@ #nat-anchor "ftp-proxy/*" #rdr-anchor "ftp-proxy/*" -#nat on $ext_if from !($ext_if) -> ($ext_if:0) +#nat on $ext_if inet from !($ext_if) -> ($ext_if:0) #rdr pass on $int_if proto tcp to port ftp -> 127.0.0.1 port 8021 #no rdr on $ext_if proto tcp from <spamd-white> to any port smtp #rdr pass on $ext_if proto tcp from any to any port smtp \ |