Hi , got freebsd ->
FreeBSD server 4.6-PRERELEASE FreeBSD 4.6-PRERELEASE #0: Sat May  4 
08:38:33 EDT 2002    root@server:/usr/obj/usr/src/sys/MAILSRV  i386
Got ipf ->
ipf: IP Filter: v3.4.27 (336)
Kernel: IP Filter: v3.4.27
Running: yes
Log Flags: 0 = none set
Default: pass all, Logging: available
Active list: 0
got ipf.rules ->
#group 10 tcp from external
#group 20 udp from external
#group 30 icmp from external

#group 10
block in log quick on tun0 proto tcp from any to server head 10
pass in quick on tun0 proto tcp from any to server port = ssh flags S/SA 
keep state group 10
pass in quick on tun0 proto tcp from any to server port = smtp flags 
S/SA keep state group 10
pass in quick on tun0 proto tcp from any to server port = domain flags 
S/SA keep state group 10
pass in quick on tun0 proto tcp from any to server port = www flags S/SA 
keep state group 10
pass in quick on tun0 proto tcp from any to server port = imap flags 
S/SA keep state group 10

#group 20
block in log quick on tun0 proto udp from any to server head 20
pass in quick on tun0 proto udp from any to server port = domain keep 
state group 20

#group 30
block in log quick on tun0 proto icmp from any to server head 30
pass in quick on tun0 proto icmp from friend to server icmp-type echo 
group 30
pass in quick on tun0 proto icmp from friend to server icmp-type 11 group 30


#group 40 - out on tun0
block out log quick on tun0 all head 40
pass out quick on tun0 proto tcp from server to any flags S/SA keep 
state group 40
pass out quick on tun0 proto udp from server to any keep state group 40
pass out quick on tun0 proto icmp from server to any keep state group 40
pass out quick on tun0 proto tcp from 192.168.0.0/24 to any flags S/SA 
keep state group 40
pass out quick on tun0 proto udp from 192.168.0.0/24 to any keep state 
group 40
pass out quick on tun0 proto icmp from 192.168.0.0/24 to any keep state 
group 40

everything goes bad ...
postfix will not start at boot time
dns server will not answer quesries ...
what am i doing wrong ?
moti

Reply via email to