Re: routing problem (with corrected scheme)

From: Julian Elischer (julian_at_elischer.org)
Date: 08/31/05

  • Next message: Digital Brain: "dhclient and ADSL modem trouble..."
    Date: Wed, 31 Aug 2005 01:26:23 -0700 (PDT)
    To: "Donatas" <donatas@lrtc.net>
    
    

    > Good morning,
    > after comprehensive tests I am glad to inform that your suggestions works
    > just fine, so - thanks for help solving our problem.
    >
    > Truth, i've got one question realated to the exampel rule below:
    >>ipfw add 1000 fwd ip4 ip from any to any out recv em0 xmit vlan{mumble}
    >
    > After several tests i have recognized that localy generated packets (like
    > icmp traffic) never matches this rule. The problem is in "xmit
    > vlan{number}" part. Is it so because of different place of packet input?
    > Transit packets come to firewall from ether_demux and passes the rule,
    > while localy generated packets come to firewall from ip_input and fails

    locally generated packets do not match recv em0

    > this rule? Using "pass" instead of "fwd" results in the same.
    >
    >
    > ----- Original Message -----
    > From: "Julian Elischer" <julian@elischer.org>
    > To: "Donatas" <donatas@lrtc.net>
    > Sent: Saturday, August 20, 2005 8:31 AM
    > Subject: Re: routing problem (with corrected scheme)
    >
    >
    >> did my sugestion work?
    >>
    >

    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Digital Brain: "dhclient and ADSL modem trouble..."

    Relevant Pages

    • Re: iptables and dhcp
      ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
      (comp.os.linux.networking)
    • Re: Trouble accessing Outlook Web Access from behind firewall
      ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
      (comp.security.firewalls)
    • Re: Visnetic and 8signs firewall LOOPHOLE Read....
      ... I said I am just reporting bug in your Firewall, ... From the Port Scan/Properties control screen: ... The firewall filtered 100% of the packets that were received. ... operating system (I'm talking Windows, ...
      (comp.security.firewalls)
    • Re: port 80 is open
      ... The firewall drops all packets initiated ... > internet the ISP router does not send the unreachable message. ... and then close the connection as your IP is seen as not connected. ...
      (comp.security.firewalls)
    • Re: strange network traffic
      ... Maybe not so wise to not have a firewall and trust a third party lurker to ... Subject: strange network traffic ... > -> connection established, following packets have neither SYN nor ...
      (Security-Basics)