Date: Tue, 17 Jul 2001 13:45:32 -0300 (ART) From: Fernando Gleiser <fgleiser@cactus.fi.uba.ar> To: Mark <mlivingstone@ottawa.com> Cc: <freebsd-questions@FreeBSD.ORG> Subject: Re: how could this PACKET get through?! Message-ID: <20010717134041.G96585-100000@cactus.fi.uba.ar> In-Reply-To: <20010717120556.A28512@tmd.df.ru>
next in thread | previous in thread | raw e-mail | index | archive | help
Without knowing your firewall rules it is difficult to tell, but a good guess is you are keeping state on the outgoing connections and the icmp packet was in response to one of those outgoing connections. Fer On Tue, 17 Jul 2001, Mark wrote: > Re, > > I am blocking most incoming icmp traffic: > > icmp-type 0 > icmp-type unreach code 3 > icmp-type unreach code 4 > icmp-type timex > > also.. im running jail, but icmp doesn't work from there.. how could this packet get through my firewall: > > Jul 17 05:12:53 ml ipmon[18381]: 05:12:52.177910 2x ed0 @0:35 p 0.so-3-0-0.XR1.ATL1.ALTER.NET -> jail PR icmp len 20 > 56 icmp 11/0 for jail,3366 - 63.108.161.50,1439 PR tcp len 20 40 IN > > Please, reply by e-mail. > > thanks in advance! > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-questions" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010717134041.G96585-100000>