From owner-freebsd-questions@FreeBSD.ORG Wed Oct 1 11:25:25 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4483916A4B3 for ; Wed, 1 Oct 2003 11:25:25 -0700 (PDT) Received: from ns2.uk.circle.com (ns0.uk.circle.com [213.249.210.7]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2029B43FA3 for ; Wed, 1 Oct 2003 11:25:24 -0700 (PDT) (envelope-from Vince.Hoffman@uk.circle.com) Received: from mime-bristol.uk.circle.com (mime-bristol.uk.circle.com [213.249.210.50]) by ns2.uk.circle.com (8.12.9/8.12.9) with ESMTP id h91ILVr1029632 for ; Wed, 1 Oct 2003 19:21:32 +0100 (BST) (envelope-from Vince.Hoffman@uk.circle.com) Received: from ex-london.uk.circle.com (unverified) by mime-bristol.uk.circle.com ; Wed, 1 Oct 2003 19:32:25 +0100 Received: by EX-LONDON with Internet Mail Service (5.5.2653.19) id ; Wed, 1 Oct 2003 19:25:29 +0100 Message-ID: <3500515B75D9D311948800508BA37955014BE0BC@EX-LONDON> From: Vince Hoffman To: "'Gary'" , FreeBSD Date: Wed, 1 Oct 2003 19:25:28 +0100 MIME-Version: 1.0 X-Mailer: Internet Mail Service (5.5.2653.19) Content-Type: text/plain; charset="iso-8859-1" Subject: RE: Firewall problem X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 01 Oct 2003 18:25:25 -0000 you have "allow ip from any to any" before your deny rules, unless my memory is seriously faulty (always possible) a packet will match that rule and never get to your deny rules. > -----Original Message----- > From: Gary [mailto:gv-list-freebsdquestions@mygirlfriday.info] > Sent: 01 October 2003 19:18 > To: FreeBSD > Subject: Firewall problem > > > I have set my firewall to > > firewall_type="open" > firewall_enable="YES" > > and when I want to drop a specific IP, I enter it manually, > it accepts it, > but it does not drop the packets.. > > I am getting a lot of virus activity on my SMTP port 25. So I > wanted to > drop a few IP ranges/addresses.. > > 00100 62054 5483792 allow ip from any to any via lo0 > 00200 0 0 deny ip from any to 127.0.0.0/8 > 00300 0 0 deny ip from 127.0.0.0/8 to any > 65000 873327 293931424 allow ip from any to any > 65100 0 0 deny tcp from 24.92.226.153 to any > 65110 0 0 deny ip from 213.191.102.86 to any > 65535 0 0 deny ip from any to any > > Yet, checking later in my SMTP logs, I am still getting pounded by the > listed addresses. Can anyone explain why this isn't working? > > Thanks, > > -- > Gary > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to > "freebsd-questions-unsubscribe@freebsd.org" >