Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 16 Oct 2001 12:54:25 -0700
From:      "Crist J. Clark" <cristjc@earthlink.net>
To:        Bjarne Wichmann Petersen <mekanix@privat.dk>
Cc:        freebsd-questions@FreeBSD.ORG
Subject:   Re: Firewall not logging
Message-ID:  <20011016125425.B4437@blossom.cjclark.org>
In-Reply-To: <20011016111536.VWHS23247.fepA.post.tele.dk@there>; from mekanix@privat.dk on Tue, Oct 16, 2001 at 01:18:19PM %2B0200
References:  <20011016085031.ZUFR22989.fepB.post.tele.dk@there> <20011016020733.F293@blossom.cjclark.org> <20011016111536.VWHS23247.fepA.post.tele.dk@there>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, Oct 16, 2001 at 01:18:19PM +0200, Bjarne Wichmann Petersen wrote:
> On Tuesday 16 October 2001 11:07, Crist J. Clark wrote:
> 
> > > # Allow all data from my network card and localhost.  Make sure you
> > > # change your network card (mine was fxp0) before you reboot.  :)
> > > $fwcmd add allow ip from any to any via lo0
> > > $fwcmd add allow ip from any to any via xl0
> >
> > All traffic is being passed by these two rules. Neither of these rules
> > log. None of the log rules that are below this are ever reached.
> 
> Hmm, I've got this from 
> http://www.freebsd.org/doc/en_US.ISO8859-1/articles/dialup-firewall/rules.html 
> with a few modifications.

That is for a machine doing dial-up. That is the machine is a gateway
with two interfaces, fxp0 and tun0. Your firewall rules only ever
refered to one interface, xl0.

> I'm not very well versed into ipfw, but I think the idea here is that trafic 
> behind the wall should go unhindered. Should I substitue "via" with "out 
> xmit" instead? Just commenting those to lines out would propably give me a 
> lot of headaches.

"Behind the wall?" Your rules did not make this machine look like a
gateway. Perhaps we don't understand your configuration.
-- 
Crist J. Clark                     |     cjclark@alum.mit.edu
                                   |     cjclark@jhu.edu
http://people.freebsd.org/~cjc/    |     cjc@freebsd.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011016125425.B4437>