On Tue, 27 Jun 2000, Andreas Meyer wrote:
> * * 127.0.0.1 y y
> tcp auth *.*.*.* y y
> * $ *.*.*.* y y
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> Setting this entry in the IP-Filter to deny access, I can�t connect
> from PC via Samba or ftp. "Access to tcp/139 or tcp/21 rejected".
>
> udp netbios-dgm 192.168.1.* 255.255.255.0 y n
> tcp netbios-ssn 192.168.1.* 255.255.255.0 y n
> tcp swat 192.168.1.* 255.255.255.0 y n
>
> Would I configure a big whole into the filter if I�d leave it set to
> "accept"? The IP-filter is also there to protect the machine as the
> Internet-client or would it be protected by the firewall too?
> In other words, the firewall protects the LAN and this server as the
> router, but as a client to the internet?
The "* $" entry is the catchall that makes the filter useful, but as such
it should come last. You need to put your Samba entries ahead of it in
order for them to work.
Fred Wright
--
To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".