Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 Aug 2013 14:36:24 -0500
From:      Dan Lists <lists.dan@gmail.com>
To:        Gary Aitken <vagabond@blackfoot.net>
Cc:        FreeBSD Mailing List <freebsd-questions@freebsd.org>
Subject:   Re: ipfw confusion
Message-ID:  <CAPW8bZ00oY7TxO-LhyvWiO9akDzoHGgmk-hCdksafV6HejEvqQ@mail.gmail.com>
In-Reply-To: <5211B5E1.6040000@blackfoot.net>
References:  <5211B5E1.6040000@blackfoot.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, Aug 19, 2013 at 1:06 AM, Gary Aitken <vagabond@blackfoot.net> wrote:

>
> ipfw list
> ...
> 21109 allow tcp from any to 12.32.44.142 dst-port 53 in via tun0 setup
> keep-state
> 21129 allow tcp from any to 12.32.36.65 dst-port 53 in via tun0 setup
> keep-state
> ...
> 65534 deny log logamount 5 ip from any to any
>
> What am I missing?
>
>
Do you have a check-state rule earlier in your rules?

1000 check-state

Dan



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAPW8bZ00oY7TxO-LhyvWiO9akDzoHGgmk-hCdksafV6HejEvqQ>