Date: Mon, 20 Dec 1999 17:43:30 -0800 (PST) From: Julian Elischer <julian@whistle.com> To: Archie Cobbs <archie@whistle.com> Cc: Darcy Buskermolen <darcy@ok-connect.com>, freebsd-ipfw@FreeBSD.ORG Subject: Re: ipfw as a statefull firewall Message-ID: <Pine.BSF.4.10.9912201742400.42166-100000@current1.whistle.com> In-Reply-To: <199912202045.MAA22866@bubba.whistle.com>
next in thread | previous in thread | raw e-mail | index | archive | help
though, you could use ipfw DIVERT to create a stateful firewall daemon. (similar to the NAT daemon) On Mon, 20 Dec 1999, Archie Cobbs wrote: > Darcy Buskermolen writes: > > I'm looking to use ipfw as a statefull firewall (much like checkpoint FW-1 > > does) for use in a one to one NAT configuration. syn/ack filter is OK, > > however thes can of course be spoofed. From my understanding this > > functionality is available in ipfilter. Is it also available in ipfw ? > > No, ipfw(8) is not stateful. > > -Archie > > ___________________________________________________________________________ > Archie Cobbs * Whistle Communications, Inc. * http://www.whistle.com > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-ipfw" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ipfw" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.10.9912201742400.42166-100000>