Re: IPFW help (dialup)

From: Ed Hurst (me_at_privacy.net)
Date: 03/09/04


Date: Tue, 09 Mar 2004 10:10:15 -0600

Alan Hicks wrote:
> From one virtual terminal you could try something like,
>
> dig www.google.com
>
> while on the other run
>
> ipfw -d list
>
> You'll have to be fast of course, but that should at least tell you if
> the dynamic rule is timing out before the DNS request finishes.

That might be a trick I'll try if it persists; however....

> I'm sure there's some variable you can set to make your dynamic rules
> last a little bit longer if this is indeed the case.

...I'll bet I can find this one. Thanks for the clue. On the actual
rules and instructions for IPFW I admit to needing a spoon feeding.
However, on most other things -- having worked with such as Linux for 8
years -- I'm content with a mere hint.

Thanks again for indulging my ignorance.

-- 
Ed Hurst
---------
return addy is a spam-catcher, used by
permission; try softedges a=t softhome d0t net


Relevant Pages

  • Re: Fw: FIN_WAIT_2
    ... It appears that inn certain conditions, when the net.inet.ip.fw.dyn_keepalive=1 (sysctl), remote clients or other ... and a new rule or dynamic rule is setup. ... I expect it virtually shut down dynamic rules too in ipfw, ...
    (freebsd-questions)
  • Re: statefull packet filter together with natd question
    ... the dynamic rule and divert to natd by putting the 'keep-state' ... option into the 'divert natd' rule. ... > seem to find a way to do that with ipfw. ... validate packet via dynamic rules ...
    (FreeBSD-Security)
  • Re: Help with ipfw and natd
    ... > ipfw add divert natd ip from any to any via $ext_if ... # Checks all outbound ntp calls and (by dynamic rule) all inbound ntp calls ... # 1) Any outbound ntp packet which has been keep-state'ed ...
    (comp.unix.bsd.freebsd.misc)
  • Re: IPFW Problems
    ... ipfw add 0430 allow log tcp from any to me 22 in via bge0 setup limit ... no rule gets added to the dynamic rule set for this connection. ... just like keep-state ... first packet of a tcp handshake, and not by an out-of-sequence tcp packet. ...
    (freebsd-questions)
  • RE: ng_netflow: testers are welcome
    ... I'm sorry, my mistake, seems like they are not reinjected on my test ... I'll continue to dig in the evening and post the results closer to local ... > To: Vasenin Alexander aka BlackSir ... > into the ipfw with rule number set. ...
    (freebsd-isp)