Народ проблема состоит в следующем есть два офиса, у одного сеть 192.168.2.x у дргугого 192.168.1.x Ситуация такая, в инет они ходят 192.168.2.x->192.168.1.x->inet В офисе 192.168.2.1 стоит шлюз. Проблема в следующем, я из 192.168.2.x имею доступ к 192.168.1.x а из 192.168.1.x к 192.168.2.x не имею. Насколько я понял проблема в редиректе Конфиг pf | Код | # $OpenBSD: pf.conf,v 1.34 2007/02/24 19:30:59 millert Exp $ # # See pf.conf(5) and /usr/share/pf for syntax and examples. # Remember to set net.inet.ip.forwarding=1 and/or net.inet6.ip6.forwarding=1 # in /etc/sysctl.conf if packets are to be forwarded between interfaces.
ext_if="rl0" int_if="sis0" vpn_if="gif0" meint="10.11.12.2/32" vpn_peer="10.11.12.1/32" table <internal> const { 192.168.2.0/24 } table <corpnet> const { 192.168.2.0/24 192.168.1.0/24 192.168.254.0/24 192.168.253.0/24 } table <proxy> const {192.168.1.243/32 192.168.2.4/32}
#table <spamd-white> persist
#set skip on lo #Traffic normalization scrub in on $ext_if all no-df scrub in on $int_if all no-df scrub out on $ext_if all no-df scrub out on $ext_if all no-df scrub out on $vpn_if all no-df scrub in on $vpn_if all no-df
#NAT on ext_if nat on $ext_if from <internal> to !<corpnet> -> ($ext_if:0)
#Redirections
rdr on $ext_if from !<corpnet> to <internal> -> ($int_if:0)
#Permit traffic #Local pass quick on { lo0 gif0 } #ICMP pass quick on $ext_if proto icmp pass quick on $int_if proto icmp pass quick on $vpn_if proto icmp
#SSH pass quick on $ext_if proto tcp from any to any port 22 keep state pass quick on $int_if proto tcp from any to any port 22 keep state # Mail #pass quick on $int_if proto tcp from any to any port 25 keep state #pass quick on $int_if proto tcp from any to any port 110 keep state #WEB #pass quick on $int_if from <proxy> to any keep state pass quick on $int_if proto tcp from <proxy> to any port 80 keep state pass quick on $int_if proto tcp from <proxy> to any port 443 keep state pass quick on $int_if proto tcp from <proxy> to any port 21 keep state pass quick on $int_if proto tcp from <proxy> to any port 20 keep state #DNS pass quick on $int_if proto udp from any to any port 53 keep state #Buch pass quick on $int_if proto tcp from any to any port 9903 keep state pass quick on $int_if proto udp from any to any port 9903 keep state #ICQ pass quick on $int_if proto tcp from any to any port 5190 keep state pass quick on $int_if proto tcp from any to any port 2802 keep state #Pass to corporate network pass in quick on $int_if from <internal> to <corpnet> keep state
pass in quick on $ext_if proto esp from $vpn_peer to ($ext_if) keep state pass out quick on $ext_if proto esp from ($ext_if) to $vpn_peer keep state pass in quick on $ext_if proto udp from any to any port 4500 keep state pass in quick on $ext_if proto udp to port 4500 keep state pass in quick on $ext_if proto udp to port 500 keep state pass out quick on $ext_if proto udp to port 500 keep state pass out quick on $ext_if proto udp to port 4500 keep state
pass in quick on $ext_if proto esp pass out quick on $ext_if proto esp pass out quick on $ext_if keep state pass in quick on enc0 proto ipencap pass out quick on enc0 proto ipencap pass out quick on $int_if keep state
# Ext if pass quick on $ext_if from $meint to any keep state pass quick on $ext_if from any to $meint keep state
#INT IF pass quick on $int_if from <internal> to <internal> keep state pass quick on $int_if from <internal> to $meint keep state
#Total deny block in inet6 from any to any #block in from any to any #block out from any to any
|
ifconfig | Код | lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 33208 groups: lo inet 127.0.0.1 netmask 0xff000000 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4 sis0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500 lladdr 00:06:4f:08:6b:eb media: Ethernet autoselect (100baseTX full-duplex) status: active inet 192.168.2.1 netmask 0xffffff00 broadcast 192.168.2.255 inet6 fe80::206:4fff:fe08:6beb%sis0 prefixlen 64 scopeid 0x1 rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500 lladdr 00:e0:4c:25:a0:96 media: Ethernet autoselect (100baseTX full-duplex) status: active inet 10.11.12.2 netmask 0xffffff00 broadcast 10.11.12.255 inet6 fe80::2e0:4cff:fe25:a096%rl0 prefixlen 64 scopeid 0x2 enc0: flags=0<> mtu 1536 gif0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1280 groups: gif physical address inet 10.11.12.2 --> 10.11.12.1 inet 10.80.255.1 --> 10.80.255.2 netmask 0xfffffffc inet6 fe80::206:4fff:fe08:6beb%gif0 -> prefixlen 64 scopeid 0x5 pflog0: flags=141<UP,RUNNING,PROMISC> mtu 33208 groups: pflog tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500 groups: tun inet 192.168.252.1 --> 192.168.252.2 netmask 0xffffffff
|
Как правильно сделать редирект? Это сообщение отредактировал(а) UserNet - 22.7.2009, 11:28
|