Is it possible to have multipe head statements for a group?
It is not possible to do this in the 3.x version of IP Filter, however this is a feature of 4.x (currently in beta). • Can you use ipnat/proxies on a bridge? Yes and no. A bridge won’t do address translation – it’s not supposed to. However, you can use IPNat’s proxies to allow connections across the statetable. For example, you could use the FTP proxy as follows: map 0/0 -> 0/0 proxy port ftp ftp/tcp To enable FTP across your bridge. Remember that at this time, the IPF FTP proxy does not support EPSV Passive connections, only plain PSV. • How do I make ping and traceroute work? This question isn’t as simple as it sounds. It takes an understanding of filtering, ICMP, UDP, ping, and traceroute. Here are some of the basics to get you started. Remember that if you are keeping state on all outgoing ICMP, then outgoing pings will automatically work. Ping uses ICMP. Specifically it entails an ICMP type 8 code 0 (herein refered to as ICMP 8/0) packet (called “echo request”) being sent to the t