From owner-freebsd-questions Wed Aug 12 00:32:04 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id AAA09596 for freebsd-questions-outgoing; Wed, 12 Aug 1998 00:32:04 -0700 (PDT) (envelope-from owner-freebsd-questions@FreeBSD.ORG) Received: from resnet.uoregon.edu (resnet.uoregon.edu [128.223.144.32]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id AAA09589 for ; Wed, 12 Aug 1998 00:32:02 -0700 (PDT) (envelope-from dwhite@resnet.uoregon.edu) Received: from localhost (dwhite@localhost) by resnet.uoregon.edu (8.8.5/8.8.8) with SMTP id AAA09992; Wed, 12 Aug 1998 00:31:34 -0700 (PDT) (envelope-from dwhite@resnet.uoregon.edu) Date: Wed, 12 Aug 1998 00:31:33 -0700 (PDT) From: Doug White To: Dan Langille cc: freebsd-questions@FreeBSD.ORG Subject: Re: ipfw rules In-Reply-To: <199808110042.MAA10419@cyclops.xtra.co.nz> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG On Tue, 11 Aug 1998, Dan Langille wrote: > I'm using ipfw and natd for my home subnet. The FreeBSD box acts as a > gateway to my ADSL connection. I'm using the simple firewall as defined > in rc.firewall. However, some of the default rules are preventing some > services from working. But I don't understand why. > > Below are the rules and a description of what they prevent when they are > enabled. If someone could explain why the rule stops what it does, I > would appreciate it. > > oif=ed0 > > # if either of the following two lines are enabled, it stops my Pegasus > # email client from accessing the POP server at my ISP > add deny all from 192.168.0.0:255.255.0.0 to any via ${oif} Stop any packets originating from 192.168.x.x from leaving this machine. What's the machine's IP? > add pass tcp from any to any setup Allows TCP connections to start but probably blocks the rest because of the above rule. Doug White | University of Oregon Internet: dwhite@resnet.uoregon.edu | Residence Networking Assistant http://gladstone.uoregon.edu/~dwhite | Computer Science Major To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message