From owner-freebsd-net Tue Jan 7 8:20:52 2003 Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1D04337B401 for ; Tue, 7 Jan 2003 08:20:51 -0800 (PST) Received: from relay.comm2000.it (doppelganger.kpnqwest.it [212.97.34.23]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3C0B343ED4 for ; Tue, 7 Jan 2003 08:20:50 -0800 (PST) (envelope-from massimo@datacode.it) Received: from insomma.local.lan (irimi.datacode.it [212.97.41.22]) by relay.comm2000.it (8.12.6/MFAGMM-19990726) with ESMTP id h07GL0Sg023765 for ; Tue, 7 Jan 2003 17:21:00 +0100 X-SMTP-Peer: irimi.datacode.it [212.97.41.22] Received: from massimo.datacode.it (massimo.datacode.it [192.168.1.13]) by insomma.local.lan (8.12.6/8.11.3) with ESMTP id h07GKEju064023 for ; Tue, 7 Jan 2003 17:20:14 +0100 (CET) (envelope-from massimo@datacode.it) Subject: mpd to work with ipfilter From: Massimo Lusetti To: freebsd-net@freebsd.org Content-Type: text/plain Content-Transfer-Encoding: 7bit X-Mailer: Ximian Evolution 1.0.8 (1.0.8-10) Date: 07 Jan 2003 17:20:18 +0100 Message-Id: <1041956418.1658.65.camel@massimo.datacode.it> Mime-Version: 1.0 Sender: owner-freebsd-net@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org I'm trying to get mpd running beside ipfilter within the same box but i'm getting strange behavior. I've got ipfilter to: pass (in|out) tcp/1723 and gre protocol on the outside interface pass (in|out) all on ng* and other rules that let pass something and block with log the rest. When i try to istantiate a connection i got a succesfull login with Win client but no network services run correctly, if i totally open the fw i got the vpn runn correctly. The strange thing is that in the log of ipfilter i get no message about packet beeing blocked !? Where's my fault ? Regards, -- Massimo.run(); To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message