Russell Fulton wrote:

> If you are running NAT how do you deal with the "we saw a portscan from
> IP x (where x is the external address of the firewall)" if it was not
> picked up by snort?

Hey Russell,

The pf(4) logs are in standard pcap(3) format; there's no seperate
type of logfile for NAT traffic. So you'll need to keep track of
what user is assigned to what IP address (probably with some sort of
table of MAC addresses stored hourly) and go from there.

I'm interested to hear how many users you'll have behind pf(4) and
what kind of preformance you'll be getting, so we'll chat off-list :)

> The residences are running NAT and using 10/8 address space.  We could,
> perhaps shoe horn them into existing address space in 130.216/16 but we
> are starting to feel a bit cramped.  Not in terms of total number of IPs
> but in having enough spare space to do big reoganisations.

Just make sure you understand pooling outbound addresses with pf; it
works great and I haven't seen it fall over on more than 50k
simultaneous connections at a local ISP. 

