bin/60538: npf(7) port range not supported in NAT rules with no port mapping

"[email protected] via gnats" <[email protected]>
Newsgroups gmane.os.netbsd.bugs
Message-ID <[email protected]>
>Number:         60538
>Category:       bin
>Synopsis:       npf(7) port range not supported in NAT rules with no port mapping
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    bin-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Tue Aug 04 18:30:00 +0000 2026
>Originator:     Emmanuel
>Release:        NetBSD 11
>Organization:
NetBSD
>Environment:
NetBSD 11.0 (GENERIC64) #0: Thu Jul 30 15:23:12 UTC 2026  [email protected]:/usr/src/sys/arch/evbarm/compile/GENERIC64 evbarm
>Description:
In a situation where you have several services listening on different ports
and you want to apply static NAT rules (without changing port numbers) for those services to the internet via a single IP, 

It is very convenient to have a single translation where you specify a port range
to be used for those services and not writing several NAT rules for every single port.

NPF currently does not allow port ranges to be used in translation segment of NAT rules.

This should be supported for static NAT rules or dynamic rules with no-port flags set
since they do not have any business rewriting port numbers. if there be need to change ports,
 then it is free to disallow.
>How-To-Repeat:
map $ext_if static proto udp $ip <-> $ext_v4 port 7078 - 7083


>Fix:
Yes, please !
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.