From 4ba82b174391bb1e122854c59bc51b9a89926cee Mon Sep 17 00:00:00 2001 From: Rui Paulo Date: Thu, 28 Jun 2012 03:30:17 +0000 Subject: Add the 'inet' keyword after the nat rule to avoid interfering with IPv6. --- share/examples/pf/faq-example1 | 2 +- share/examples/pf/pf.conf | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) (limited to 'share/examples/pf') diff --git a/share/examples/pf/faq-example1 b/share/examples/pf/faq-example1 index 91942f616d4f..e9b240fbd903 100644 --- a/share/examples/pf/faq-example1 +++ b/share/examples/pf/faq-example1 @@ -26,7 +26,7 @@ set skip on lo scrub in # nat/rdr -nat on $ext_if from !($ext_if) -> ($ext_if:0) +nat on $ext_if inet from !($ext_if) -> ($ext_if:0) nat-anchor "ftp-proxy/*" rdr-anchor "ftp-proxy/*" diff --git a/share/examples/pf/pf.conf b/share/examples/pf/pf.conf index 299999df8041..d97b4ede16e3 100644 --- a/share/examples/pf/pf.conf +++ b/share/examples/pf/pf.conf @@ -16,7 +16,7 @@ #nat-anchor "ftp-proxy/*" #rdr-anchor "ftp-proxy/*" -#nat on $ext_if from !($ext_if) -> ($ext_if:0) +#nat on $ext_if inet from !($ext_if) -> ($ext_if:0) #rdr pass on $int_if proto tcp to port ftp -> 127.0.0.1 port 8021 #no rdr on $ext_if proto tcp from to any port smtp #rdr pass on $ext_if proto tcp from any to any port smtp \ -- cgit v1.2.3