From owner-freebsd-security@FreeBSD.ORG Thu Apr 22 16:26:17 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DD7C716A4CE for ; Thu, 22 Apr 2004 16:26:17 -0700 (PDT) Received: from ibague.terra.com.br (ibague.terra.com.br [200.154.55.225]) by mx1.FreeBSD.org (Postfix) with ESMTP id 9ADEC43D48 for ; Thu, 22 Apr 2004 16:26:16 -0700 (PDT) (envelope-from suporte@wahtec.com.br) Received: from potosi.terra.com.br (potosi.terra.com.br [200.154.55.131]) by ibague.terra.com.br (Postfix) with ESMTP id 2EA0DECB93 for ; Thu, 22 Apr 2004 20:26:15 -0300 (BRT) Received: from wahottisray (unknown [200.96.65.150]) (authenticated user arisjr) by potosi.terra.com.br (Postfix) with ESMTP id 8FE63370022 for ; Thu, 22 Apr 2004 20:26:14 -0300 (BRT) From: "Aristeu Gil Alves Jr" To: "Freebsd-Security" Date: Fri, 23 Apr 2004 20:26:53 -0300 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0) X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Importance: Normal Subject: ipfilter/ipfw + bridge + out checking X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Apr 2004 23:26:18 -0000 Hi all. I didn't find any thread discussing it, sorry if I am re-posting the same subject. Is there a way to check the ipfilter/ipfw out-flow with bridge? Is it implemented? I've heard its not done due a performance issue (it's writen in ipf-howto), but performance is not the main goal for me in this single situation. I would like to have the stateful firewall and the bridge _fully_ working together. Best regards, --aristeu