OpenBSD Journal

Securing Small Networks with OpenBSD: Changes in pf: More on NAT

Contributed by jose on from the jacek's-corner dept.

In the latest Securing Small Networks with OpenBSD , Jacek writes about some of the new NAT features in PF . He gives several good recipes and ideas, and explores some of the more interesting things you can do with inbound NAT. Worth a read, and thanks again Jacek!

(Comments are closed)


Comments
  1. By janus () janus...errornet...de on mailto:janus...errornet...de

    ...just like those strange iptables-scripts *sigh*
    I think in pf this many macros doesn't really make sense. In many cases its ok, but this is _really_ awfull.
    But anyhow, it's a nice example for anyone who doesn't likes to read the manpage.

    Comments
    1. By Matt () on

      I agree, this is one case where macros really don't make the task any easier. They do make it painfully obvious what he is doing (which was probably the point) but I doubt a newbie will be able to sort through all the cruft to figure out how to make his own ruleset.

      It's always good to have something new to read I guess.

      Comments
      1. By janus () janus...errornet... on mailto:janus...errornet...

        > It's always good to have something new to read I guess.
        That's true in any case :)

  2. By hooha () none@nowhere.not on mailto:none@nowhere.not

    is when the OpenBSD Gazetteer will be released.
    My b-day is May 19, and I want to put it on my list :-D

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]