sockstat |grep 8668
root natd 459 3 div4 *:8668 *:*
sysctl -a |grep forward
net.inet.ip.forwarding: 1
net.inet.ip.fastforwarding: 0
traceroute -Svni rl0 192.168.0.3
traceroute to 192.168.0.3 (192.168.0.3), 128 hops max, 40 byte packets
1 192.168.0.3 48 bytes to 192.168.1.3 0.418 ms 0.394 ms 0.331 ms (0% loss)
traceroute -Svni fxp0 192.168.0.3
traceroute to 192.168.0.3 (192.168.0.3), 128 hops max, 40 byte packets
1 192.168.0.3 48 bytes to 192.168.0.1 0.420 ms * 0.347 ms (33% loss) что-то здесь не так
Код: Выделить всё
00010 180 11880 allow icmp from any to any icmptypes 0,8,11
00030 2448443 2196335246 allow ip from 192.168.0.0/24 to any via fxp0
00050 120 6240 allow ip from any to any via lo0
00100 208654 293602707 divert 8668 ip from not 192.168.0.0/24 to any in via tun0
00101 0 0 check-state
00130 1655 238050 skipto 500 udp from any to any dst-port 7,53,123,4000,5190 out via tun0 keep-state
00135 552281 596951506 skipto 500 tcp from any to any dst-port 7,20,21,22,25,37,43,53,67,68,80,81,83,85,443,445,110,210,2802,5190,8080,3218,5999,8030 out via tun0 setup keep-state
00140 10 2208 skipto 500 icmp from any to any out via tun0 keep-state
00150 0 0 deny ip from 192.168.0.0/24 to any in via tun0
00155 0 0 deny ip from 172.16.0.0/12 to any in via tun0
00160 0 0 deny ip from 10.0.0.0/8 to any in via tun0
00165 0 0 deny ip from 127.0.0.0/8 to any in via tun0
00170 0 0 deny ip from 0.0.0.0/8 to any in via tun0
00175 0 0 deny ip from 169.254.0.0/16 to any in via tun0
00180 0 0 deny ip from 192.0.2.0/24 to any in via tun0
00185 0 0 deny ip from 204.152.64.0/23 to any in via tun0
00190 0 0 deny ip from 224.0.0.0/3 to any in via tun0
00210 0 0 deny tcp from any to any dst-port 137 in via tun0
00215 0 0 deny tcp from any to any dst-port 138 in via tun0
00220 117 5680 deny tcp from any to any dst-port 139 in via tun0
00225 317 15476 deny tcp from any to any dst-port 445 in via tun0
00230 0 0 deny ip from any to any frag in via tun0
00240 177 45252 deny tcp from any to any established in via tun0
00250 0 0 deny tcp from any to any dst-port 113 in via tun0
00260 1083 75019 deny log ip from any to any in via tun0
00300 783 49101 deny log ip from any to any out via tun0
00500 140026 10271304 divert 8668 ip from 192.168.0.0/24 to any out via tun0
06000 553946 597191764 allow ip from any to any
06500 0 0 deny log logamount 5 ip from any to any
65535 0 0 allow ip from any to any
Желаю вам:ни стука в харде,ни глюка в софте.