[nycbug-talk] OpenBSD PF help

Barry Kominik bkominik at gmail.com
Mon Jun 11 12:23:51 EDT 2007

I'm having problems getting a pf filter working. I must be doing something
simple wrong, anybody have any advice?

I have two public routable IP blocks, let's say and
The colo routes both networks to my handoff. I have the int0 connected to
the handoff from the co-lo and ext0 configured as the I have
net.inet.ip.forwarding=1. Shouldn't basic routing work without even enabling
the firewall? Hosts on the 2 network can ping trough to the, but not beyond. Hosts on the internet can see but nothing on the 2. network. I can get this to work by setting up
a bridge between the interfaces, but this strikes me as incorrect. Am I
missing something simple? If not I can pay for some consulting time.

