Сейчас правила такие:ext_if_a = "bfe0"
int_if = "re0"
ext_gw_a = "87.224.151.1"
tcp_svc = "ssh smtp domain"
udp_svc = "domain"
tcp_rdr = "http ftp rdp ircd mysqld 50000:50020 8021"
host_rdr = "192.168.250.10"
scrub in
nat on $ext_if_a from 192.168.250.10 -> $ext_if_a
rdr pass on $ext_if_a proto tcp from 87.224.151.16 to port { $tcp_rdr } -> 192.168.250.10
rdr on $ext_if_a proto tcp to port { $tcp_rdr } tag EXT_IF_A -> 192.168.250.10
# Защита от IP spoofing.
pass quick on { lo $int_if }
antispoof quick for { lo $int_if }
# По умолчанию блокировать входящий трафик на внешних интерфейсах.
# Для TCP соединений возвращать RST.
block in on { $ext_if_a }
block return-rst in on { $ext_if_a } proto tcp
# Направить исходящие пакеты в канал, соответствующий адресу источника.
pass out route-to ($ext_if_a $ext_gw_a) from ($ext_if_a) to !(self:network) keep state
# Установить маршрут для ответа на входящие пакеты для переадресованных
# TCP сервисов.
pass in reply-to ($ext_if_a $ext_gw_a) proto tcp flags S/SA tagged EXT_IF_A keep state
# Разрешить входящие ICMP ping пакеты, обслуживаемые UDP и TCP сервисы.
pass in on $ext_if_a reply-to ($ext_if_a $ext_gw_a) inet proto icmp icmp-type echoreq code 0 keep state
pass in on $ext_if_a inet proto icmp from ($ext_if_a:network) icmp-type echoreq code 0 keep state
pass in on $ext_if_a reply-to ($ext_if_a $ext_gw_a) proto udp to port { $udp_svc } keep state
pass in on $ext_if_a proto udp from ($ext_if_a:network) to port { $udp_svc } keep state
pass in on $ext_if_a reply-to ($ext_if_a $ext_gw_a) proto tcp to port { $tcp_svc } flags S/SA keep state
pass in on $ext_if_a proto tcp from ($ext_if_a:network) to port { $tcp_svc } flags S/SA keep state
настройка сети на сервере в локалке такая:
Windows IP Configuration
Host Name . . . . . . . . . . . . : xeon
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Lan1(151.16;Sky;Insis):
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 EB Network Connection with I/O Acceleration
Physical Address. . . . . . . . . : 00-15-17-0E-EB-46
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.250.10
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 87.224.213.1
Ethernet adapter Lan2(151.109):
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 EB Network Connection with I/O Acceleration #2
Physical Address. . . . . . . . . : 00-15-17-0E-EB-47
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 172.100.100.10
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 172.100.100.1
Таблица маршрутизации на винде:
IPv4 Route Table
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x80004 ...00 15 17 0e eb 47 ...... Intel(R) PRO/1000 EB Network Connection with I/O Acceleration #2
0x90003 ...00 15 17 0e eb 46 ...... Intel(R) PRO/1000 EB Network Connection with I/O Acceleration
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 172.100.100.1 172.100.100.10 1
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
172.100.100.0 255.255.255.0 172.100.100.10 172.100.100.10 1
172.100.100.0 255.255.255.0 172.100.100.1 172.100.100.10 1
172.100.100.10 255.255.255.255 127.0.0.1 127.0.0.1 1
172.100.255.255 255.255.255.255 172.100.100.10 172.100.100.10 1
192.168.250.0 255.255.255.0 192.168.250.10 192.168.250.10 1
192.168.250.0 255.255.255.0 192.168.250.1 192.168.250.10 1
192.168.250.10 255.255.255.255 127.0.0.1 127.0.0.1 1
192.168.250.255 255.255.255.255 192.168.250.10 192.168.250.10 1
224.0.0.0 240.0.0.0 172.100.100.10 172.100.100.10 1
224.0.0.0 240.0.0.0 192.168.250.10 192.168.250.10 1
255.255.255.255 255.255.255.255 172.100.100.10 172.100.100.10 1
255.255.255.255 255.255.255.255 192.168.250.10 192.168.250.10 1
Default Gateway: 172.100.100.1
===========================================================================
Persistent Routes:
Network Address Netmask Gateway Address Metric
192.168.250.0 255.255.255.0 192.168.250.1 1
172.100.100.0 255.255.255.0 172.100.100.1 1
причем, в таком случае роутов - маршрут идет все равно через дефолтный.
надо еще прописывать
маршрут до внешнего интервейса на рутере данной сети.
Цитата:
Persistent Routes:
Network Address Netmask Gateway Address Metric
192.168.250.0 255.255.255.0 192.168.250.1 1
172.100.100.0 255.255.255.0 172.100.100.1 1
87.224.151.R1 255.255.255.255 192.168.250.1 1
87.224.151.R2 255.255.255.255 172.100.100.1 1
пытаюсь зайти с работы:
Код:
self tcp 192.168.250.10:80 <- 87.224.151.16:80 <- 82.193.139.2:2730 CLOSED:SYN_SENT
82.193.139.2 - я