From owner-freebsd-security@FreeBSD.ORG Fri May 9 17:25:30 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 468C237B401 for ; Fri, 9 May 2003 17:25:30 -0700 (PDT) Received: from praetor.linc-it.com (hardtime.linuxman.net [66.147.26.65]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4F0BC43FDD for ; Fri, 9 May 2003 17:25:29 -0700 (PDT) (envelope-from fullermd@over-yonder.net) Received: from mortis.over-yonder.net (adsl-33-236-134.jan.bellsouth.net [67.33.236.134]) (using TLSv1 with cipher EDH-RSA-DES-CBC3-SHA (168/168 bits)) (No client certificate requested) by praetor.linc-it.com (Postfix) with ESMTP id 9D3CD1543B; Fri, 9 May 2003 19:25:27 -0500 (CDT) Received: by mortis.over-yonder.net (Postfix, from userid 100) id DE1A520F03; Fri, 9 May 2003 19:25:25 -0500 (CDT) Date: Fri, 9 May 2003 19:25:25 -0500 From: "Matthew D. Fuller" To: Danny Carroll Message-ID: <20030510002525.GC97056@over-yonder.net> References: <1052299663.086db7b178457@www.dannysplace.com> <003101c314cf$930ceef0$e464a8c0@llama> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <003101c314cf$930ceef0$e464a8c0@llama> User-Agent: Mutt/1.4i-fullermd.1 X-Editor: vi X-OS: FreeBSD cc: freebsd-security@freebsd.org Subject: Re: how to configure a FreeBSD firewall to pass IPSec? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 10 May 2003 00:25:30 -0000 On Wed, May 07, 2003 at 09:33:45PM +0200 I heard the voice of Danny Carroll, and lo! it spake thus: > > deny log logamount 500 ip from any to 192.168.0.0/24 via xl0 ^^ Shouldn't that be /16? Which would also obviate the need for: > deny log logamount 500 ip from 192.168.50.0/24 to any in recv xl0 -- Matthew Fuller (MF4839) | fullermd@over-yonder.net Systems/Network Administrator | http://www.over-yonder.net/~fullermd/ "The only reason I'm burning my candle at both ends, is because I haven't figured out how to light the middle yet"