From owner-freebsd-questions@FreeBSD.ORG Wed Apr 28 16:50:54 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id AA49A1065673 for ; Wed, 28 Apr 2010 16:50:54 +0000 (UTC) (envelope-from dan@dan.emsphone.com) Received: from email1.allantgroup.com (email1.emsphone.com [199.67.51.115]) by mx1.freebsd.org (Postfix) with ESMTP id 7172E8FC1D for ; Wed, 28 Apr 2010 16:50:52 +0000 (UTC) Received: from dan.emsphone.com (dan.emsphone.com [199.67.51.101]) by email1.allantgroup.com (8.14.0/8.14.0) with ESMTP id o3SGonZs009741 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Wed, 28 Apr 2010 11:50:50 -0500 (CDT) (envelope-from dan@dan.emsphone.com) Received: from dan.emsphone.com (smmsp@localhost [127.0.0.1]) by dan.emsphone.com (8.14.4/8.14.3) with ESMTP id o3SGonaq014955 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Wed, 28 Apr 2010 11:50:49 -0500 (CDT) (envelope-from dan@dan.emsphone.com) Received: (from dan@localhost) by dan.emsphone.com (8.14.4/8.14.3/Submit) id o3SGon20014954 for freebsd-questions@freebsd.org; Wed, 28 Apr 2010 11:50:49 -0500 (CDT) (envelope-from dan) Date: Wed, 28 Apr 2010 11:50:49 -0500 From: Dan Nelson To: freebsd-questions@freebsd.org Message-ID: <20100428165049.GH14572@dan.emsphone.com> References: <20100428123425.706d6e51@scorpio.seibercom.net> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20100428123425.706d6e51@scorpio.seibercom.net> X-OS: FreeBSD 8.0-STABLE User-Agent: Mutt/1.5.20 (2009-06-14) X-Virus-Scanned: clamav-milter 0.96 at email1.allantgroup.com X-Virus-Status: Clean X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-2.0.2 (email1.allantgroup.com [199.67.51.78]); Wed, 28 Apr 2010 11:50:50 -0500 (CDT) X-Scanned-By: MIMEDefang 2.45 Subject: Re: Unknown IPFW log message X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 Apr 2010 16:50:54 -0000 In the last episode (Apr 28), Jerry said: > In the security.log, I have been noticing the following: > > Apr 28 12:04:20 scorpio kernel: ipfw: 4400 Deny P:2 192.168.1.1 224.0.0.1 in via nfe0 > > I have not been able to document what the "P:2" stands for. Neither, have > I been able to find out if I should continue to allow the block to > continue. Googling has turned up a few posts that seem to indicate that I > should allow it. Since "P:2" is where either "tcp" or "udp" would be, it's probably the protocol number. /etc/protocols says igmp 2 IGMP # internet group management protocol I don't know what igmp is used for, though. -- Dan Nelson dnelson@allantgroup.com