Ik heb een FreeBSD-machine staan als firewall, daarachter staat onderandere mijn webserver. Ik heb IPfilter draaiende en dat werkt ook best goed, zolang ik mijn verbindingen op de firewall laat eindigen. Ik kan dus niet naar mijn webserver toe van buiten af. Vanaf mijn firewall kan ik wel naar de webserver. SSH vanaf mijn werk naar mijn firewall gaat ook prima. Iemand enig idee wat er fout is in mijn scripts?
ipf.rules
ipnat.rules
Sorry voor de layout wijziging....
ipf.rules
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
| # IPFilter -script # ep0 - interface to DSL (10.0.0.0/24) # tun0 - interface to ISP (xxx.xxx.xxx.xxx) # xl0 - interface to LAN (172.19.127.0/24) # # Incoming rules on tun0 # block in quick on tun0 all head 1 pass in quick on tun0 proto tcp from <vriends-ip>/32 to xxx.xxx.xxx.xxx/32 port = 22 keep state group 1 pass in quick on tun0 proto tcp from <werk-ip>/32 to xxx.xxx.xxx.xxx/32 port = 22 keep state group 1 pass in quick on tun0 proto tcp from any to xxx.xxx.xxx.xxx/32 port = 80 group 1 # WWW pass in quick on tun0 proto tcp from any to xxx.xxx.xxx.xxx/32 port = 25 group 1 # SMTP # LAN # Limit access from the lan to other networks # pass in quick on xl0 proto tcp/udp from any to any keep state |
ipnat.rules
code:
1
2
3
4
5
6
7
| # Do NAT on LAN map tun0 172.19.127.0/24 -> xxx.xxx.xxx.xxx/32 portmap tcp/udp 10000:60000 map tun0 172.19.127.0/24 -> xxx.xxx.xxx.xxx/32 # Make http and smtp available from outside rdr tun0 xxx.xxx.xxx.xxx/32 port 80 -> 172.19.127.1 port 80 rdr tun0 xxx.xxx.xxx.xxx/32 port 25 -> 172.19.127.1 port 25 |
Sorry voor de layout wijziging....