From owner-freebsd-bugs@FreeBSD.ORG Wed Mar 11 18:10:03 2009 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id C358C1065676 for ; Wed, 11 Mar 2009 18:10:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id B1B978FC20 for ; Wed, 11 Mar 2009 18:10:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.3/8.14.3) with ESMTP id n2BIA30B013651 for ; Wed, 11 Mar 2009 18:10:03 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.3/8.14.3/Submit) id n2BIA3Ba013650; Wed, 11 Mar 2009 18:10:03 GMT (envelope-from gnats) Date: Wed, 11 Mar 2009 18:10:03 GMT Message-Id: <200903111810.n2BIA3Ba013650@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Maxim Konovalov Cc: Subject: Re: misc/132553: ipfw doesnt understand ftp-data port X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Maxim Konovalov List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Mar 2009 18:10:04 -0000 The following reply was made to PR misc/132553; it has been noted by GNATS. From: Maxim Konovalov To: Chistoph Weber-Fahr Cc: bug-followup@freebsd.org Subject: Re: misc/132553: ipfw doesnt understand ftp-data port Date: Wed, 11 Mar 2009 21:04:09 +0300 (MSK) > >Description: > this ipfw clause should work and did work on older systems: > > # ipfw add 1770 allow tcp from any to any ftp-data keep-state > > but now it produces > > ipfw: unrecognised option [-1] ftp-data > > this is regardless of the addresses used - you could also use any addresses or networks instead of "any". > > ftp-data is in /etc/services as always: > > # grep ftp-data /etc/services > ftp-data 20/tcp #File Transfer [Default Data] > ftp-data 20/udp #File Transfer [Default Data] > > $ ipfw -n add 1770 allow tcp from any to any ftp\\-data keep-state 01770 allow tcp from any to any dst-port 20 keep-state works for me. -- Maxim Konovalov