On Tue, 27 Jun 2000, Andreas Meyer wrote:

> *    *            127.0.0.1                   y  y  
> tcp  auth         *.*.*.*                     y  y
> *    $            *.*.*.*                     y  y
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> Setting this entry in the IP-Filter to deny access, I can�t connect
> from PC via Samba or ftp. "Access to tcp/139 or tcp/21 rejected".
> 
> udp  netbios-dgm  192.168.1.*  255.255.255.0  y  n
> tcp  netbios-ssn  192.168.1.*  255.255.255.0  y  n
> tcp  swat         192.168.1.*  255.255.255.0  y  n
> 
> Would I configure a big whole into the filter if I�d leave it set to
> "accept"? The IP-filter is also there to protect the machine as the
> Internet-client or would it be protected by the firewall too?
> In other words, the firewall protects the LAN and this server as the
> router, but as a client to the internet?

The "* $" entry is the catchall that makes the filter useful, but as such
it should come last.  You need to put your Samba entries ahead of it in
order for them to work.

                                        Fred Wright

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to