History log of /freebsd-11.0-release/sbin/natd/natd.8
Revision Date Author Comments
(<<< Hide modified files)
(Show modified files >>>)
# 303975 11-Aug-2016 gjb

Copy stable/11@r303970 to releng/11.0 as part of the 11.0-RELEASE
cycle.

Prune svn:mergeinfo from the new branch, and rename it to RC1.

Update __FreeBSD_version.

Use the quarterly branch for the default FreeBSD.conf pkg(8) repo and
the dvd1.iso packages population.

Approved by: re (implicit)
Sponsored by: The FreeBSD Foundation

# 302408 08-Jul-2016 gjb

Copy head@r302406 to stable/11 as part of the 11.0-RELEASE cycle.
Prune svn:mergeinfo from the new branch, as nothing has been merged
here.

Additional commits post-branch will follow.

Approved by: re (implicit)
Sponsored by: The FreeBSD Foundation


# 267803 23-Jun-2014 joel

mdoc: remove superfluous paragraph macros.


# 267667 20-Jun-2014 bapt

use .Mt to mark up email addresses consistently (part1)

PR: 191174
Submitted by: Franco Fichtner <franco@lastsummer.de>


# 236809 09-Jun-2012 joel

mdoc: fix a few badly nested blocks.


# 235873 24-May-2012 wblock

Fixes to man8 groff mandoc style, usage mistakes, or typos.

PR: 168016
Submitted by: Nobuyuki Koganemaru
Approved by: gjb
MFC after: 3 days


# 223713 01-Jul-2011 sem

Fix a typo.

Approved by: kib


# 179937 22-Jun-2008 mav

Add exit_delay parameter to control daemon exit delay after signal.

PR: bin/58696
Submitted by: sp@alkor.ru


# 175971 04-Feb-2008 ru

Improve rev. 1.63. Document -instance and -globalport options.
Add a MULTIPLE INSTANCES section which provides an example of
setting up natd in multi-instance mode (based on the notes.natd
file from phk@).

Submitted by: "Andrey V. Elsukov" <bu7cher@yandex.ru>
Reviewed by: ru


# 175552 21-Jan-2008 trhodes

Note that the punch_fw option does not work in securelevel 3 and Xref init.8.
Bump .Dd.

PR: 41807


# 174591 14-Dec-2007 maxim

o Markup and grammar fixes.


# 174508 10-Dec-2007 ceri

Bump .Dd for r1.63; fix small nit from the same.


# 174506 10-Dec-2007 phk

Add a bit more detailed description about a configuration
file format and about using NAT "instances".

Submitted by: "Andrey V. Elsukov" <bu7cher@yandex.ru>


# 140295 15-Jan-2005 ru

Eliminate macro calls inside literal displays.


# 120372 23-Sep-2003 marcus

Add Cisco Skinny Station protocol support to libalias, natd, and ppp.
Skinny is the protocol used by Cisco IP phones to talk to Cisco Call
Managers. With this code, one can use a Cisco IP phone behind a FreeBSD
NAT gateway.

Currently, having the Call Manager behind the NAT gateway is not supported.
More information on enabling Skinny support in libalias, natd, and ppp
can be found in those applications' manpages.

PR: 55843
Reviewed by: ru
Approved by: ru
MFC after: 30 days


# 118875 13-Aug-2003 ru

- Clarify the port range syntax in -redirect_port.

PR: docs/46286

- "IP number" -> "IP address", for consistency.


# 118873 13-Aug-2003 ru

Added an option to specify an alternate PID file.

PR: bin/37159
Submitted by: "Aleksandr A. Babaylov" <.@babolo.ru>


# 116319 13-Jun-2003 ru

If the -proxy_only option is used, the -alias_address/-interface
options are not required.

Suggested by: Vaclav Petricek
MFC after: 2 weeks


# 111674 28-Feb-2003 ru

Don't pretend natd(8) doesn't work with ppp(8) interfaces.
While there's probably a better way to achieve the same,
nothing precludes us from using natd(8) on tun(4) links.

Noticed by: bde


# 109727 23-Jan-2003 ru

Fixed Charles' e-mail here too.


# 101810 13-Aug-2002 ru

can not -> cannot.


# 101796 13-Aug-2002 ru

mdoc(7) police: canonize FreeBSD in e-mail address.


# 99501 06-Jul-2002 charnier

The .Nm utility


# 99382 03-Jul-2002 archie

Update my email address.


# 87647 11-Dec-2001 ru

s/sysctl -w/sysctl/


# 86955 27-Nov-2001 ru

Make -log_ipfw_denied active by default with -verbose.

Discussed with: phk


# 86954 27-Nov-2001 ru

Fixed (local) style bugs in previous revision.


# 85770 31-Oct-2001 phk

Do not uselessly whine in syslog about packets denied by ipfw rules.

Set 'log_ipfw_denied' option if you want the old behaviour.

PR: 30255
Submitted by: Flemming "F3" Jacobsen <fj@batmule.dk>
Reviewed by: phk
MFC after: 4 weeks


# 81251 07-Aug-2001 ru

mdoc(7) police:

Avoid using parenthesis enclosure macros (.Pq and .Po/.Pc) with plain text.
Not only this slows down the mdoc(7) processing significantly, but it also
has an undesired (in this case) effect of disabling hyphenation within the
entire enclosed block.


# 79530 10-Jul-2001 ru

mdoc(7) police: removed HISTORY info from the .Os call.


# 75670 18-Apr-2001 ru

mdoc(7) police: normalize .Nd.


# 71895 01-Feb-2001 ru

mdoc(7) police: split punctuation characters + misc fixes.


# 68960 20-Nov-2000 ru

mdoc(7) police: use the new features of the Nm macro.


# 68823 16-Nov-2000 ru

Describe -deny_incoming better, highlight some keywords,
add myself to the AUTHORS section.


# 68754 15-Nov-2000 ben

more removal of trailing periods from SEE ALSO.


# 63300 17-Jul-2000 ru

Suggest looking at rc.conf(5) on how to start natd(8) during boot.

Submitted by: dcs


# 62252 29-Jun-2000 ru

"Ease understanding" of how -punch_fw works.

Reviewed by: sheldonh


# 62160 27-Jun-2000 ru

Added new option (-punch_fw) which allows to `punch holes'
in the ipfirewall(4) for incoming FTP/IRC DCC connections.

Submitted by: Rene de Vries <rene@canyon.demon.nl>
Rewritten by: ru


# 62157 27-Jun-2000 ru

- mdoc(7) style cleanup
- new version of security note from alex.


# 62128 26-Jun-2000 alex

Back out both previous commits.
The first one got screwed up by me because of rev 1.33, which was
incorrectly merged into my patches by myself, and so Ruslan (maintainer)
asked me to back them out.

Ruslan was ok with the second one, but since it needs rework, it'll be
readded later, when it doesn't conflict with the backout of the first one.

Pointy hat: alex
Beer on next meeting: ru


# 62122 26-Jun-2000 alex

Add note about security concerns w/o a firewall but other machines
on your LAN to the "RUNNING NATD" introduction.

In a different way requested by:
PR: 18802
Submitted by: Zachary K Drew <drew0054@tc.umn.edu>


# 62121 26-Jun-2000 alex

mdoc style cleanup.

Reviewed by: sheldonh


# 61864 20-Jun-2000 ru

Remove ``pptpalias'' since this is now done transparently by libalias(3).


# 60784 22-May-2000 sheldonh

Fix a small grammar nit, with the maintainer's implicit approval.


# 60683 18-May-2000 ru

Add new option (-target_addr) to control how to deal with incoming packets
not associated with any pre-existing link.

Submitted by: brian


# 59921 03-May-2000 ru

New option: -redirect_proto.


# 59703 27-Apr-2000 ru

Load Sharing using IP Network Address Translation (RFC 2391, LSNAT).


# 58946 02-Apr-2000 brian

Correct Charles Mott's email address
Requested by: cmott@scientech.com


# 57668 01-Mar-2000 sheldonh

Remove single-space hard sentence breaks. These degrade the quality
of the typeset output, tend to make diffs harder to read and provide
bad examples for new-comers to mdoc.


# 57512 26-Feb-2000 brian

Suggest ppp -nat, not ppp -alias


# 52683 30-Oct-1999 mpp

Minor grammar fix.


# 51963 06-Oct-1999 ru

Fixed the description of how packets re-enter IP firewall filter.

Suggested by: Ari Suutari <ari@suutari.iki.fi>


# 51063 07-Sep-1999 ru

Config file parser changes:

- Trailing spaces and empty lines are ignored.
- A `#' sign will mark the remaining of the line as a comment.

Reviewed by: Ari Suutari <ari@suutari.iki.fi>


# 50476 28-Aug-1999 peter

$Id$ -> $FreeBSD$


# 49994 18-Aug-1999 chris

Bad cross-reference of getservbyname(2) changed to getservbyname(3)

Reviewed by: ru


# 49164 28-Jul-1999 ru

Back out previous commit.


# 48063 21-Jun-1999 brian

Mention that data going from one internal address to another will
not be processed by natd.
Requested by: Ludwig Pummer <ludwigp@bigfoot.com>


# 47121 13-May-1999 brian

/sbin/natd portrange documentation and bugfix
Submitted by: Ruslan Ermilov <ru@ucb.crimea.ua>
PR: 11690

3.2 candidate ?


# 45498 08-Apr-1999 eivind

Add a comment that natd is made for use with NICs, not PPP links - I'm
tired of the five people each day that ask me how to set up natd for
use with PPP.


# 44558 07-Mar-1999 brian

Upgrade (almost) to natd 2.0b1

- Transparent proxy support.
- PERMANENT_LINK IS NOW OBSOLETE, use redirect_port instead.
- Drop support for early FreeBSD 2.2 versions
- If separate input & output sockets are being used
use them to find out packet direction instead of
normal mechanism. This can be handy in complex environments
with multiple interfaces.
- PPTP redirect support by Dru Nelson <dnelson@redwoodsoft.com> added.
- Logging enhancements from Martin Machacek <mm@i.cz> added.

Obtained from: Ari Suutari <ari@suutari.iki.fi>


# 37650 15-Jul-1998 jkoshy

Fix inconsistent port numbering in man page.

PR: 7250
Submitted-by: Norihiro Kumagai <kuma@jp.freebsd.org>


# 37633 14-Jul-1998 jkoshy

Add $Id$.

PR: 7249


# 37368 04-Jul-1998 brian

Suggest port 8668 rather than 6668 for natd.
6668 is IRC.


# 35266 18-Apr-1998 brian

Fix incorrect flag spec
PR: 6339 (part of)
Submitted by: Chris Dillon <cdillon@wolves.k12.mo.us>


# 34809 23-Mar-1998 charnier

.Sh AUTHOR -> .Sh AUTHORS. Use .An/.Aq.


# 32856 29-Jan-1998 brian

Make it clear that aliasing is done on the public interface, not
the private one.


# 30554 18-Oct-1997 brian

Add -redirect_port and -redirect_address to the
synopsis.


# 30059 02-Oct-1997 charnier

Use err(3). Change firewall to firewall_enable in man page according to
/etc/rc.conf.


# 29988 29-Sep-1997 wosch

Sort cross refereces in section SEE ALSO.


# 29562 18-Sep-1997 charnier

Typo.


# 28956 31-Aug-1997 eivind

Fix my e-mail address. Old work addres is no good.


# 28045 10-Aug-1997 brian

- Buffer space problem found by Sergio Lenzi <lenzi@bsi.com.br>
fixed. Natd now waits with select(2) for buffer space
to become available if write fails.
- Packet aliasing library upgraded to 2.2.

Submitted by: Ari Suutari <suutari@iki.fi>


# 26891 24-Jun-1997 brian

Suggest using /etc/services entry rather than a
number in the "ipfw add divert" example.


# 26810 22-Jun-1997 jkh

sysconfig -> rc.conf


# 26782 22-Jun-1997 brian

This commit was generated by cvs2svn to compensate for changes in r26781,
which included commits to RCS files with non-trunk default branches.


# 26781 22-Jun-1997 brian

Bring natd into main source tree now that the
pppd/natd combination works ok.

Submitted by: Ari Suutari <ari.suutari@ps.carel.fi>