Solaris 10, ipfilter rdr rules and virtual interfaces

"Terry Dawson" <[email protected]>
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <4028_1242276589_4A0BA2EC_4028_2448_1_E420E6E58B8C1F4084717440F028356803E98C2D@34093-C3-EVS2.exchange.rackspace.com>
Hello,
I'm not terribly experienced with ipfilter, or Solaris for that matter,
and have a problem for which I've been unable to find a solution using
my usual resources (FAQ, google web, google groups, google some more).

I'm trying to configure an rdr rule for packets received on a virtual
interface (ce0:1), but the ipnat command fails, complaining about the
interface name. This appears to be valid because the grammar provided in
the ipnat.conf man page suggests ifname must match:
[a-zA-Z][a-zA-Z]*[0-9]. Clear virtual interfaces names don't.

ipnat.conf:
#
rdr ce0:1 0.0.0.0/0 port 3891 -> 127.0.0.1 port 389

# ipnat -f /etc/ipf/ipnat.conf
syntax error error at ":", line 2

What am I doing wrong? Is there something else I should be doing?

regards
Terry

---
Terry Dawson
Solution Architect, Elanti Systems Inc.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.