Re: ipfilter på FreeBSD 4.3

From: Flemming Laugaard (none@Flemming.Laugaard--uni-c.dk.lh.bsd-dk.dk)
Date: Mon 28 May 2001 - 11:03:56 CEST


Date: Mon, 28 May 2001 11:03:56 +0200 (CEST)
From: Flemming Laugaard <none@Flemming.Laugaard--uni-c.dk.lh.bsd-dk.dk>
To: Claus Guttesen <none@cguttesen--yahoo.dk.lh.bsd-dk.dk>
Subject: Re: ipfilter på FreeBSD 4.3

Hej Claus

> # Min regel - start
> pass in quick on fxp0 proto tcp from any to any port =
> 80 S/SA
> # Min regel - slut
>
> Som I ser, 80 (http) tilladt, men tilføjes S/SA så
> sker der ingenting, lynx siger blot 'HTTP request
> sent, waiting for response.'

Du skal nok have 'keep state' på reglen. Så fungerer det.

-- 
Med venlig hilsen
Flemming Laugaard
CISSP

--------------------------------------------------------- Don't look now... But I think a paranoid is following us!



This archive was generated by hypermail 2b30 : Wed 15 Nov 2006 - 18:24:08 CET