Код: Выделить всё
#rc.conf
hostname="localhost"
inet_enable="NO"
local_startup=/etc/rc.d
firewall_enable="YES"
firewall_script="/etc/rc.firewall"
firewall_logging="YES"
tcp_extension="NO"
tcp_drop_synfin="YES"
icmp_drop_redirect="YES"
icmp_log_redirect="YES"
natd_enable="YES"
natd_program="/sbin/natd"
natd_interface="rl0"
natd_flags="-f /etc/natd.conf"
squid_enable="YES"
pptpd_enable="YES"
ifconfig_rl0="inet 22.22.22.22 netmask 255.255.255.224"
ifconfig_vr0="inet 11.11.11.11 netmask 255.255.255.224"
ifconfig_xl0="inet 192.168.21.1 netmask 255.255.255.0"
ifconfig_xl0_alias0="inet 192.168.25.1 netmask 255.255.255.0"
gateway_enable="yes"
defaultrouter="22.22.22.222"
kern_securelevel_enable="NO"
keymap="ru.koi8-r"
nfs_reserved_port_only="YES"
sendmail_enable="YES"
sshd_enable="YES"
tcp_extensions="YES"
named_enable="YES"
ipacctd_enable="YES"
ipacctd_flags="-v"
ipacctd_rules="xl0"
ipacctd_rule_xl0_flags="-p 10001 -f /var/log/traffic_xl0.log"
ipacctd_rule_xl0_pid="/var/run/ipacctd.xl0"
rc.firewall
Код: Выделить всё
00100 check-state
00200 divert 10001 ip from any to any via xl0
00300 queue 5 tcp from any to 192.168.25.20
00400 queue 6 tcp from any to 192.168.25.21
00500 queue 7 tcp from any to 192.168.25.22
00600 queue 8 tcp from any to 192.168.21.3
00700 queue 9 tcp from any to 192.168.21.0/24
00800 queue 10 tcp from any to 192.168.25.0/24
01600 allow ip from any to any via xl0
01700 allow esp from any to any
01800 allow ip from any to any via gif0
01900 divert 8886 tcp from any to 22.22.22.22 3389 via rl0
02000 divert 8887 tcp from any to 11.11.11.11 3389 via rl0
02100 divert 8668 ip from any to any out xmit rl0
02300 divert 8668 ip from any to 22.22.22.22 in recv rl0
02400 divert 8886 tcp from 192.168.21.2 to any 3389 via rl0
02500 divert 8887 tcp from 192.168.21.2 to any 3389 via rl0
02600 allow tcp from any to 192.168.21.2 3389 via any
02700 allow ip from 192.168.21.2 to any
02800 allow tcp from any to me 1723
02900 allow gre from any to any
03000 allow ip from any to any via tun0
04000 allow icmp from any to any
04100 allow tcp from any 9091 to any
04200 allow tcp from any to any 9091
04300 allow tcp from any 80,21,20,9193,5190,443,25,110,8080,7777 to any
04500 allow tcp from any 143,993,2020,33333,3389,1723,3250,24468 to any
04700 allow tcp from any 3389,4899 to any
65535 deny ip from any to any
добавил
ipfw add 2050 fwd 11.11.11.111 ip from any to 213.191.0.0/24
где последним сеть голдена
Код: Выделить всё
relay# tcpdump -i vr0 port 3389
tcpdump: listening on vr0
22:05:00.343700 fttb.ur.ru.62553 > 11.11.11.11.rdp: S 1195246708:1195246708(0) win 64512 <mss 1420,nop,nop,sackOK> (DF)
22:05:00.343720 11.11.11.11.rdp > fttb.ur.ru.62553: R 0:0(0) ack 1195246709 win 0
тепрь ответы идут, однако не работает rdp(
ну и получил неприятность, что меня выкинуло с другого интерфейса
ipfw add 2350 fwd 11.11.11.111 ip from any to 213.191.0.0/24
Код: Выделить всё
relay# tcpdump -i vr0 port 3389
tcpdump: listening on vr0
22:00:19.572548 fttb.ur.ru.62433 > 11.11.11.11.rdp: S 2719445670:2719445670(0) win 64512 <mss 1420,nop,nop,sackOK> (DF)
22:00:19.572615 22.22.22.22.rdp > fttb.ur.ru.62433: R 0:0(0) ack 2719445671 win 0
однако...
ну и ничего не соединяется...