Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 20 Dec 1999 17:43:30 -0800 (PST)
From:      Julian Elischer <julian@whistle.com>
To:        Archie Cobbs <archie@whistle.com>
Cc:        Darcy Buskermolen <darcy@ok-connect.com>, freebsd-ipfw@FreeBSD.ORG
Subject:   Re: ipfw as a statefull firewall
Message-ID:  <Pine.BSF.4.10.9912201742400.42166-100000@current1.whistle.com>
In-Reply-To: <199912202045.MAA22866@bubba.whistle.com>

next in thread | previous in thread | raw e-mail | index | archive | help
though, you could use ipfw DIVERT to create a stateful firewall daemon.
(similar to the NAT daemon)

On Mon, 20 Dec 1999, Archie Cobbs wrote:

> Darcy Buskermolen writes:
> > I'm looking to use ipfw as a statefull firewall (much like checkpoint FW-1
> > does) for use in a one to one NAT configuration. syn/ack filter is OK,
> > however thes can of course be spoofed. From my understanding this
> > functionality is available in ipfilter. Is it also available in ipfw ?
> 
> No, ipfw(8) is not stateful.
> 
> -Archie
> 
> ___________________________________________________________________________
> Archie Cobbs   *   Whistle Communications, Inc.  *   http://www.whistle.com
> 
> 
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-ipfw" in the body of the message
> 



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ipfw" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.10.9912201742400.42166-100000>