From owner-freebsd-ipfw@FreeBSD.ORG Sun Apr 6 09:18:12 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F342F37B401 for ; Sun, 6 Apr 2003 09:18:10 -0700 (PDT) Received: from mout2.freenet.de (mout2.freenet.de [194.97.50.155]) by mx1.FreeBSD.org (Postfix) with ESMTP id CB3F943FAF for ; Sun, 6 Apr 2003 09:18:08 -0700 (PDT) (envelope-from ino-qc@spotteswoode.de.eu.org) Received: from [194.97.55.147] (helo=mx4.freenet.de) by mout2.freenet.de with asmtp (Exim 4.14) id 192CqN-0004HU-E5 for freebsd-ipfw@freebsd.org; Sun, 06 Apr 2003 18:18:07 +0200 Received: from pd90559e3.dip.t-dialin.net ([217.5.89.227] helo=spotteswoode.dnsalias.org) by mx4.freenet.de with asmtp (ID inode@freenet.de) (Exim 4.14 #2) id 192CqM-00047O-IF for freebsd-ipfw@freebsd.org; Sun, 06 Apr 2003 18:18:06 +0200 Received: (qmail 5005 invoked by uid 0); 6 Apr 2003 16:18:05 -0000 Date: 6 Apr 2003 18:18:05 +0200 Message-ID: From: "clemens fischer" To: "Sereciya Kurdistani" In-Reply-To: <20030405174853.GA94738@kurdistan.ath.cx> (Sereciya Kurdistani's message of "Sat, 5 Apr 2003 09:48:53 -0800") References: <20030403182847.GC23675@kurdistan.ath.cx> <20030403135048.D92663-100000@diana.northnetworks.ca> <20030405174853.GA94738@kurdistan.ath.cx> User-Agent: Gnus/5.090017 (Oort Gnus v0.17) Emacs/21.3.50 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii cc: freebsd-ipfw@freebsd.org Subject: Re: Quick IPFW Question Concerning Sendmail X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Apr 2003 16:18:12 -0000 Sereciya Kurdistani : > vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv > ipfw add NNNN check-state > ipfw add NNNN allow { udp or tcp } from any to any dst-port smtp,auth,smtps out via tun0 keep-state > ipfw add NNNN allow log tcp from any to any dst-port smtp,smtps in via tun0 > ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ > > This way, you don't have to allow any ports open for any incoming traffic not matched > by the stateful rules, ;) are you sure this does what you want? i don't see the customary anti-spoofing rules and there's a lot to be said for keeping state especially on _incoming_ connections. if these are all your rules, then what about incoming SMTP and AUTH on port 113? i imagine your rules allowing _you_ to query others for AUTH data, but you don't allow others this privilege. clemens