From owner-freebsd-ipfw@FreeBSD.ORG Sun Mar 6 14:55:16 2011 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 63AAF106566B; Sun, 6 Mar 2011 14:55:16 +0000 (UTC) (envelope-from ctfreebsd@gmail.com) Received: from mail-gy0-f182.google.com (mail-gy0-f182.google.com [209.85.160.182]) by mx1.freebsd.org (Postfix) with ESMTP id 0E7268FC0A; Sun, 6 Mar 2011 14:55:15 +0000 (UTC) Received: by gyh4 with SMTP id 4so1559405gyh.13 for ; Sun, 06 Mar 2011 06:55:15 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:date:message-id:subject:from:to :content-type; bh=gZvJ1FFEtWs2Uaj9Ub2TISF1SdZJZcvujNDq/8G4o9k=; b=HeGOfU+os9ohHP86mcmB6FMBSJNnu4ox7i1at5zyNxnnbI1BgKrWGBedP+L7+SBteu UpHjRe8+45duefGqboNR4+3f0oJC6GujIuhLcxe668bY1pL1MQa7JBiqi+BB4pjgK0Fu msEqx4vD05lA33C/CXVSpM9GKULqCPmmc22iQ= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=JObVC8iOUX5P7U4ugGjcb61Ia7xiD1mj0nwYISM7HgCUNeaEBMd1ToXlR6hFlFlvAI G/DF7N++zIfVpBTOjQf3cRO5AbPOYr15tZebk7KFla4gUXfNUFprZLNltmMTruBLLM2k Ntn/wq8ER9vfUFST9WMYHJ7rRpWzCFwxYVQGc= MIME-Version: 1.0 Received: by 10.151.122.3 with SMTP id z3mr3310894ybm.89.1299421432647; Sun, 06 Mar 2011 06:23:52 -0800 (PST) Received: by 10.147.171.19 with HTTP; Sun, 6 Mar 2011 06:23:52 -0800 (PST) Date: Sun, 6 Mar 2011 16:23:52 +0200 Message-ID: From: Dave Johnson To: freebsd-ipfw@freebsd.org, freebsd-stable@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: Subject: Kernel Update / IPFW not working X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Mar 2011 14:55:16 -0000 Hi all An IPFW problem when going from release to stable on 8.2 An help gladly accepted LOG ON Flushed all rules. 00010 allow ip from 127.0.0.1 to 127.0.0.1 via lo0 00030 divert 8668 ip from any to any via bge0 ipfw: getsockopt(IP_FW_ADD): Invalid argument 50000 allow ip from any to any Firewall rules loaded. Starting natd. rc.conf defaultrouter="192.168.0.1" gateway_enable="YES" hostname="xxx.xxx.xxx" ifconfig_bge0="inet 192.168.0.11 netmask 255.255.255.0" ifconfig_em0="inet 192.168.1.2 netmask 255.255.255.0" keymap="us.iso" moused_enable="YES" sshd_enable="YES" firewall_enable="YES" firewall_script="/etc/rc.firewall" natd_program="/sbin/natd" natd_enable="YES" natd_interface="bge0" natd_flags="-f /etc/natd.conf" dhcpd_enable="NO" dhcpd_flags="-q" dhcpd_conf="/usr/local/etc/dhcpd.conf" dhcpd_ifaces="em0" dhcpd_withumask="022" natd.conf interface bge0 use_sockets yes same_ports yes log #redirect_port tcp 192.168.1.189:3389 3389 #redirect_port tcp 192.168.1.53:5500 5500 #!/bin/sh /sbin/ipfw -f flush /sbin/ipfw -f pipe flush #Nat Rules /sbin/ipfw add 10 allow ip from 127.0.0.1 to 127.0.0.1 via lo0 /sbin/ipfw add 30 divert natd all from any to any via bge0 #Forward to Transparent Proxy Server #/sbin/ipfw add 10001 fwd 127.0.0.1,3128 tcp from any to any 80 #/sbin/ipfw add 10010 fwd 127.0.0.1,3128 tcp from 10.0.21.2 to any 80 /sbin/ipfw add 10001 fwd 127.0.0.1,3128 tcp from any to any 80 /sbin/ipfw add 50000 allow ip from any to any KERNEL options IPFIREWALL options IPFIREWALL_VERBOSE options IPFIREWALL_VERBOSE_LIMIT=5 options IPFIREWALL_DEFAULT_TO_ACCEPT options IPDIVERT options DUMMYNET Regards