Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 24 Aug 2015 09:39:05 -0400
From:      Allan Jude <allanjude@freebsd.org>
To:        freebsd-current@freebsd.org
Subject:   Re: ipfw rules for connect port 993
Message-ID:  <55DB1E79.9030108@freebsd.org>
In-Reply-To: <55DB16B7.2000602@gyrec.cz>
References:  <55DB16B7.2000602@gyrec.cz>

next in thread | previous in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--nUV2ToKLB30b9JM2960QarbeIRsx42Jds
Content-Type: text/plain; charset=iso-8859-2
Content-Transfer-Encoding: quoted-printable

On 2015-08-24 09:05, Petr Chochol=E1=E8 wrote:
> Hello,
>=20
> I would like to ask you for advice. I can not connect to imap.gmail.com=

> on port 993 from my local network. My LAN is behind freeBSD server with=

> IPFW. Server has two network cards rl0=3DInternet and
> re0=3DLAN(10.0.0.0/16). Tcpdump on re0 shows three SYN packets without
> answers.  What rules should i create?
>=20
> I tried someting like this, without success:
> #ipfw add 01500 allow ip from 10.0.0.0/16 to any in via re0
>=20
>=20
>=20
> Thank you very much for any advice and your patience
>=20
> Petr Chochol=E1=E8
> Brno, Czech Republic
>=20
> _______________________________________________
> freebsd-current@freebsd.org mailing list
> https://lists.freebsd.org/mailman/listinfo/freebsd-current
> To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.o=
rg"

We would need to see all of your current firewall rules (ipfw show)

You'll want to tcpdump on rl0, to see if the packet is being forwarded.

Do you have the machine configured as a gateway? (gateway_enable=3D"YES"
in /etc/rc.conf)

Are you doing NAT (Network Address Translation) to remap the internal
(10.0.0.0/16) addresses to your internet routable IP?

--=20
Allan Jude


--nUV2ToKLB30b9JM2960QarbeIRsx42Jds
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (MingW32)

iQIcBAEBAgAGBQJV2x5/AAoJEBmVNT4SmAt+9MgP/1Pg9OWSv6z/J1GWDr70enyO
NY6ZAl1OYwgP/ziiT+3kYL+CcwjsduzQRdchDjmYJCOHW7xF2kigHm5rcdgrNozg
hPXgV2a2To95SFK4rXK6nQMkqUcA2Ne5+yGXT4W/sS3cF8RZhl7bFJieeSANfhsh
Os+mt90QquCnTVvwr3zfmCmtomeIItWMABhfgNFoA3LEQEFhHkaUzoNYMjv+17/3
afZclhNWkkin3OSfWQjrW2n1j4ofslVdbFFoeJchXtFKdMIYqQ5cJx6oHBPIpYuk
j4zNMBUIFHOQWjvZ8SOmnUSQvzsycp/WFJSX9EG1M+7LyI5tfd2qavNup2FmffpS
ysTzoa1iYYTYUtV8YbK6v5FWll/0893qn1Zb9PFof3rKoGhED+snv2Be1ft2v0/d
NwqWTryMF0oBm3sVr3MKoFFfYkx4hBmyZYV3etRNcPBGFrOGgqv82k7OQ4z7caHu
I0P5Btf0qmFZW24mvf6QO5pk3cgmPjJjqJPVEEBCgFQihznWPG/yI9IGqJwG8aKK
9DapPvtY+EhpgBdmMaAj6qp2BG69xynURq4gYN9q4g6Lx2p4hlbR71FXvRTU7erp
o6bwwnt8iy3kxoPalP3ZwUWN5Cu55Pe9AID/F88JTl0ncVSqGcW4nv66vo2wys4j
faVg7eYNuT6vTOcKc8pp
=97ba
-----END PGP SIGNATURE-----

--nUV2ToKLB30b9JM2960QarbeIRsx42Jds--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?55DB1E79.9030108>