4、ipfw规则:
00010 allow ip from any to 192.168.1.9
00011 allow ip from 192.168.1.9 to any
00090 divert 3333 udp from 192.168.100.0/24 to any dst-port 53 recv bridge0
00095 divert 3333 udp from 192.168.6.6 53 to any out via bridge0
00200 nat 10 ip from any to any out via re0
00500 nat 10 ip from any to any in via re0
65530 allow ip from any to any
附:pppoe接入实际用规则
/sbin/ipfw add 1000 divert 3333 udp from any to not 192.168.6.6 dst-port 53 recv ng*
/sbin/ipfw add 1001 divert 3333 udp from 192.168.6.192 53 to any recv vlan550
/sbin/natd -p 3333 -proxy_only -proxy_rule "server 192.168.6.192 proto udp" -log -reverse