assumption: eth0 internal interface
ppp0 external interface
ipnatadm -I -W eth0 -i -b -D real-address/32 -N 10.x.y.z/32
add option '-o' to log matching packets (your question nr. 2) -> if you don't get any logs, the rule doesn't match any packets...
You may use the local (eth0) address as 'real-address', but with that setup you can't reach that system from the outside any longer, so if you do that, specify a destination port (range), so that only some packets are forwarded to the inside. |
Messages
Outline:
still doesn't work... here a detailed scribble... by Sven Woltmann, 5/19/99