Solaris 10, ipfilter rdr rules and virtual interfaces
"Terry Dawson" <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.ipfilter |
|---|---|
| Message-ID | <4028_1242276589_4A0BA2EC_4028_2448_1_E420E6E58B8C1F4084717440F028356803E98C2D@34093-C3-EVS2.exchange.rackspace.com> |
Hello, I'm not terribly experienced with ipfilter, or Solaris for that matter, and have a problem for which I've been unable to find a solution using my usual resources (FAQ, google web, google groups, google some more). I'm trying to configure an rdr rule for packets received on a virtual interface (ce0:1), but the ipnat command fails, complaining about the interface name. This appears to be valid because the grammar provided in the ipnat.conf man page suggests ifname must match: [a-zA-Z][a-zA-Z]*[0-9]. Clear virtual interfaces names don't. ipnat.conf: # rdr ce0:1 0.0.0.0/0 port 3891 -> 127.0.0.1 port 389 # ipnat -f /etc/ipf/ipnat.conf syntax error error at ":", line 2 What am I doing wrong? Is there something else I should be doing? regards Terry --- Terry Dawson Solution Architect, Elanti Systems Inc.