Re: firewalling with tunnels, and/or ipv6

From: Brooks Davis (brooks_at_one-eyed-alien.net)
Date: 12/21/04

  • Next message: Qukasz_Bromirski?=: "Re: OpenBGPd?"
    Date: Mon, 20 Dec 2004 21:55:29 -0800
    To: Charlie Schluting <charlie@schluting.com>
    
    
    

    On Mon, Dec 20, 2004 at 06:05:16PM -0800, Charlie Schluting wrote:
    > Ok, I've got a v6 tunnel, and to make it work I had to "allow ipv6 from
    > <endpoint>" in ipfw. From what I understand, I have to make a completely
    > different set of rules for ipv6, and load them using the -6 flag.
    >
    > Correct so far?

    ip6fw is an entierly different beast from ipfw. There is no -6 option
    to ipfw. Use ip6fw instead. If 6.x we should have ipv6 support in ipfw
    and ip6fw should be gone.

    -- Brooks

    -- 
    Any statement of the form "X is the one, true Y" is FALSE.
    PGP fingerprint 655D 519C 26A7 82E7 2529  9BF0 5D8E 8BE9 F238 1AD4
    
    



  • Next message: Qukasz_Bromirski?=: "Re: OpenBGPd?"

    Relevant Pages

    • FreeBSD Security Advisory: FreeBSD-SA-01:08.ipfw
      ... based on an old version of ipfw and does not contain as many features. ... Due to overloading of the TCP reserved flags field, ipfw and ip6fw ... incorrectly treat all TCP packets with the ECE flag set as being part ...
      (FreeBSD-Security)
    • Re: IPv6 and IPFW
      ... far as you use ipfw as a KLD module. ... IP6FW in the long run. ... complete in-place replacement for IP6FW as IPFW2 syntax has diverted from the ...
      (freebsd-stable)
    • ipfw/ip6fw Ipv6 forwarding
      ... I could not find a way to do ipv6 packet forwarding with ip6fw or ipfw. ... Karim Fodil-Lemelin ...
      (freebsd-net)
    • Re: ip6fw without ipfw?
      ... start) also enables ipfw? ... It sure surprised me when I was exploring IPv6 setup and I enabled ... and ipfw came up and locked me out via ... I loaded the ip6fw module and ipfw is not loaded. ...
      (freebsd-questions)
    • Re: ip6fw without ipfw?
      ... start) also enables ipfw? ... ip6fw without configuring the IPv4 rc.firewall. ... and ipfw came up and locked me out via ... I loaded the ip6fw module and ipfw is not loaded. ...
      (freebsd-questions)