[EMAIL PROTECTED] wrote:
> 
> As described below, I am still unable to deploy IPFilter because it
> blocks communication among trusted hosts within my domain. Since the
> Email below, I've explicitly coded "pass in quick ..." statements for
> each IP address in my subnet, yet blocks still occur. 
>  
> What am I missing?

According to these lines:

> Computer 123.456.78.11:
> 29/11/2006 12:16:35.785428 eri0 @0:18 b 123.456.78.59,52740 ->
> 123.456.78.11,32772 PR tcp len 20 40 -AF IN
> 29/11/2006 12:16:36.713333 eri0 @0:18 b 123.456.78.59,52740 ->
> 123.456.78.11,32772 PR tcp len 20 40 -AF IN

It's blocked by rules 18, and NOT by OOW. Since you haven't included 18
rules, I suspect you're not giving us your whole ruleset. Without your whole
ruleset, people are unlikely to look into this very far.

-- 
Phil Dibowitz                             [EMAIL PROTECTED]
Open Source software and tech docs        Insanity Palace of Metallica
http://www.phildev.net/                   http://www.ipom.com/

"Never write it in C if you can do it in 'awk';
 Never do it in 'awk' if 'sed' can handle it;
 Never use 'sed' when 'tr' can do the job;
 Never invoke 'tr' when 'cat' is sufficient;
 Avoid using 'cat' whenever possible" -- Taylor's Laws of Programming


Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to