Re: nat.conf to NAT or not to NAT.

On 26 Oct 2001 at 9:50, Jan Johansson wrote:

> Hi,
> I have tried to understand the nat.conf man page but I can figure
> out how to do this.
> We have a number of "black" nets and three routable. I would like
> to have the black nets NATed when we go outside our gateway
> router but not inside.
> Connection is like.
> Internet <-> Cisco <-> Routable ips <-> Gateway <-> black nets
> Gateway has 17 interfaces, 1 with routable ip and 16 different
> black nets.
> So, would the rules be like
> our_nets={,, }
> nat on if1 ! our_nets from to any ->

Internal traffic will never go out on your external interface unless 
routing is really screwed up.

You just need to specify your private addresses in the nat rule:

nat on $extif from to any -> $extip


