Re: ipfw2 filtering on bridge

2005-06-23 Thread Alin-Adrian Anton
Ben wrote: I'm sorry, I can't send this to the list because my messages to the list bounce because reverse DNS isn't set up. No worries, thanks a lot for answering. This is funny, I just set this up for the first time yesterday except I set everything up to have no IP addresses so that the

ipfw2 filtering on bridge

2005-06-22 Thread Alin-Adrian Anton
Hi there, I've been running into some problems with what is supposed to be a filtering bridge with IPFW, on FreeBSD 5.4-REL0. IPFW has been compiled into kernel: options BRIDGE options IPFIREWALL options IPFIREWALL_DEFAULT_TO_ACCEPT options IPDIVERT a

Re: ipfw2 test utility

2004-06-19 Thread Viktor Ivanov
On Sat, 19 Jun 2004 19:20:37 +0300, Anton Alin-Adrian <[EMAIL PROTECTED]> wrote: > > See nemesistcp from ports. Isn't this a tool to generate packets, like ipsend(1) and iptest(1)? > > I doubt. Faster with logging & scripts. Do you mean ipfw's log option? If I wanted to see which rule number a

Re: ipfw2 test utility

2004-06-19 Thread Anton Alin-Adrian
Viktor Ivanov wrote: Hello -hackers. I'm thinking about an utility to test a simple packet against the machine's firewall (ipfw2 to be more specific). I needed it because on some of my routers the configuration got complicated and the rule count is too high. And sometimes I need to s

Re: ipfw2 test utility

2004-06-19 Thread Bjoern A. Zeeb
On Sat, 19 Jun 2004, Viktor Ivanov wrote: > count is too high. And sometimes I need to see quickly what a > colleague have done to the firewall and why it's not working as > expected. use rcs or cvs for tracking changes -- Bjoern A. Zeeb bzeeb at Zabbadoz dot NeT __

ipfw2 test utility

2004-06-19 Thread Viktor Ivanov
Hello -hackers. I'm thinking about an utility to test a simple packet against the machine's firewall (ipfw2 to be more specific). I needed it because on some of my routers the configuration got complicated and the rule count is too high. And sometimes I need to see quickly what a coll

Re: ipfw2 problem

2004-01-04 Thread Leo Bicknell
In a message written on Sun, Jan 04, 2004 at 05:32:17PM +0800, Ganbold wrote: > me what will happen when net.inet.ip.fw.dyn_count reaches > net.inet.ip.fw.dyn_max value? As a random passing thought... Anytime a new dynamic rule is denied due to reaching dyn_max, a new counter, eg, "dropped_dyn_

RE: ipfw2 problem

2004-01-04 Thread Ganbold
urned off one-pass? > -Original Message- > From: Ganbold [mailto:[EMAIL PROTECTED] > Sent: January 4, 2004 4:32 AM > To: [EMAIL PROTECTED] > Cc: [EMAIL PROTECTED] > Subject: ipfw2 problem > > > Hi, > > I'm using FreeBSD 5.2-current machine for firewa

ipfw2 problem

2004-01-04 Thread Ganbold
Hi, I'm using FreeBSD 5.2-current machine for firewall. It is configured as a bridged ipfw2 firewall. Also this machine works a a traffic shaper using ip dummynet features. The machine has 2GHz Pentium 4 CPU and 128MB RAM and 3 Intel Pro 100MB cards. 2 cards are used for bridging. Every

Re: kern/50216: kernel panic on 5.0-current when use ipfw2 with dynamic rules

2003-09-30 Thread Kang Liu
I reproduced it on the latest 5.1current. Here is the backtrace: # GNU gdb 5.2.1 (FreeBSD) Copyright 2002 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Ty

Re: IPFW2

2003-09-23 Thread Luigi Rizzo
On Tue, Sep 23, 2003 at 12:28:07PM -0400, Matthew George wrote: ... > > you can count the traffic with dynamic rules (but this does not go > > to the logfile), not sure what you mean by 'see the transfered data file' > > from ipf(5): > > LOGGING >When a packet is logged, with either the

Re: IPFW2

2003-09-23 Thread Tim Kientzle
On Mon, Sep 22, 2003 at 08:07:13PM +0200, Uwe Klann wrote: From the Log file IPFW:- "Sep 22 00:24:13 muc /kernel: ipfw: 3300 Accept TCP 217.10.213.30:4418 217.9.121.209:21 in via fxp0" How can I extend on FreeBSD 4.8 (ipfw2) the log contens to see the tranfered data File and the amoun

Re: IPFW2

2003-09-23 Thread Matthew George
" > > > > How can I extend on FreeBSD 4.8 (ipfw2) the log contens to see the tranfered > > data File and the amount of bytes went out? Thank you in advance for your > > you can count the traffic with dynamic rules (but this does not go > to the logfile), not su

Re: IPFW2

2003-09-22 Thread Luigi Rizzo
On Mon, Sep 22, 2003 at 08:07:13PM +0200, Uwe Klann wrote: > Hi All, > > >From the Log file IPFW:- > "Sep 22 00:24:13 muc /kernel: ipfw: 3300 Accept TCP 217.10.213.30:4418 > 217.9.121.209:21 in via fxp0" > > How can I extend on FreeBSD 4.8 (ipfw2) the log conten

IPFW2

2003-09-22 Thread Uwe Klann
Hi All, >From the Log file IPFW:- "Sep 22 00:24:13 muc /kernel: ipfw: 3300 Accept TCP 217.10.213.30:4418 217.9.121.209:21 in via fxp0" How can I extend on FreeBSD 4.8 (ipfw2) the log contens to see the tranfered data File and the amount of bytes went out? Thank you in advance

Re: Question about divert in ipfw2 on 5.0 release

2003-02-28 Thread Maxim Konovalov
> We're diverting all received and sended packets (from\to port Y) to divert port X. > But these rules are not working together with ipfw2 (5.0 Release). Each single rule > works fine, but when i combine them together only first of them triggers. The order > doesn't matter. > >

Question about divert in ipfw2 on 5.0 release

2003-02-28 Thread denb
. But these rules are not working together with ipfw2 (5.0 Release). Each single rule works fine, but when i combine them together only first of them triggers. The order doesn't matter. What am I doing wrong? To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-hacke