Re: Still can't use ADSL, PF problem

From: Johnathan Doe (johnathan_doe_at__NOSPAM_fastmail.com.au_I_SAID_NO_SPAM!)
Date: 08/23/04


Date: Tue, 24 Aug 2004 04:51:17 +1000

clvrmnky wrote:

> I'm not sure what your exact problem is that was caused by tweaking PF
> as a non-privileged user, but PF talks to the network devices via some
> privileged devices. I've found that using sudo when running any pfctl
> command is necessary to do anything. The rulesets should just work when
> reapplied. No reboot is necessary.

Thanks very much for your help. I did need to reboot a few times, although
I am not sure why. I was obviously doing something wrong.
 
> Use a PASV connection. The DIR commands will cause apparent lockups on
> (some) firewalled connections unless the ftp client is setup to connect
> passively. I'm hand-waving here, I know, but the FTP issue may be
> unrelated to anything else you are experiencing. Google for the details.

I will check out what Google has to say. But then, why can't I access
websites when using lynx? It manages to connect and sometimes 200 OK comes
through, but then it hangs. :-(

I must have a dud firewall rule in there somewhere.

> The admins here at work have all been heard to say the exact opposite.
> My own users have heard me exclaim how hard OpenBSD "rocks" while
> tweaking the edge box running OpenBSD.

Yes, but I am not an admin. I am a (l)user. It might be straight forward
for people who know what they're doing. The documentation is very
reasonable, but again, I am lost when working on the system. So while
things are clearly explained, like having an internal and external
interface for the firewall, I didn't know what these things were. I
guessed and thought internal was rl0 and external was tun0 on my system.
But I don't know.
 
> I second the advice to look at the FAQ examples and build your ruleset
> up from there. The examples reflect real-world use.

Didn't work for me for some reason. I used the FAQ examples, and Googled
and found at least five other examples. None of them worked. I also tried
everything with two different ADSL modems.

I must be doing something seriously wrong that's obvious to everyone else
but not to me...

Cheers
Johnathan



Relevant Pages

  • Re: Vista Hacked
    ... other words what confirmation do you have that the original install was ... Probably the best solution for a firewall is to use a router, ... Either should show active connections, many of which will be your machine ... If you have Google toolbar or update manager installed then random ...
    (microsoft.public.windows.vista.performance_maintenance)
  • Re: Critique Symnantec "Google PacK" Virus Scan; MS Firewall:Thanx. D. Lipman
    ... |> at the moment with Office SP3, I have the Google Service Pack ... I am at present using the XP 95 MS firewall. ... | for Symantec, but what a botheration (I could use shorter Anglo Saxon ... On Demand - When the user causes a scan to be perform either manually or via a schedule. ...
    (alt.comp.anti-virus)
  • My Sygate PFPro loves Google, hates everyone else
    ... Running Sygate Personal Firewall Pro 5.5 build 2525 on Windows XP ... weird that only Google is ... The problem is Sygate PFP because all the sites are accessible if I ... change the firewall option to Allow All which is not a good way to use ...
    (comp.security.firewalls)
  • Re: Pipex Web Problems
    ... A first step towards diagnosis is whether you can ping by ... Just done that and Google home page appears. ... As an experiment you then try turning the firewall off, ... Windows has tools for diagnosing connection problems, ...
    (uk.telecom.broadband)
  • =?iso-8859-1?Q?Re:_Unm=F6glich_=22google=22_zu_erreichen?=
    ... Beat Leuppi wrote: ... > ich habe hier auf einem PC ein komisches Problem: ich kann google ... Die Firewall kontrolliert per IP-Nummer (die ... Next by Date: ...
    (microsoft.public.de.german.win2000.sonstiges)