From owner-freebsd-ipfw@FreeBSD.ORG Thu Aug 2 12:47:47 2007 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 495DD16A417 for ; Thu, 2 Aug 2007 12:47:47 +0000 (UTC) (envelope-from danny@dannysplace.net) Received: from mail.dannysplace.net (mail.dannysplace.net [213.133.54.210]) by mx1.freebsd.org (Postfix) with ESMTP id 0A07F13C481 for ; Thu, 2 Aug 2007 12:47:47 +0000 (UTC) (envelope-from danny@dannysplace.net) Received: from 124-171-210-201.dyn.iinet.net.au ([124.171.210.201] helo=[192.168.10.2]) by mail.dannysplace.net with esmtpa (Exim 4.62 (FreeBSD)) (envelope-from ) id 1IGZzu-000F7B-VY for freebsd-ipfw@freebsd.org; Thu, 02 Aug 2007 22:41:54 +1000 Message-ID: <46B1D261.4050907@dannysplace.net> Date: Thu, 02 Aug 2007 22:47:29 +1000 From: Danny Carroll User-Agent: Thunderbird 1.5.0.12 (Windows/20070509) MIME-Version: 1.0 CC: freebsd-ipfw@freebsd.org References: <46B170F0.3020702@dannysplace.net> <46B18737.5070102@yandex.ru> In-Reply-To: <46B18737.5070102@yandex.ru> X-Enigmail-Version: 0.94.1.0 Content-Type: text/plain; charset=KOI8-R Content-Transfer-Encoding: 7bit X-SA-Exim-Connect-IP: 124.171.210.201 X-SA-Exim-Mail-From: danny@dannysplace.net X-Spam-Checker-Version: SpamAssassin 3.2.1 (2007-05-02) on ferrari.dannysplace.net X-Spam-Level: * X-Spam-Status: No, score=1.6 required=8.0 tests=ALL_TRUSTED,AWL, DKIM_POLICY_SIGNSOME,MISSING_HEADERS,TVD_RCVD_IP autolearn=disabled version=3.2.1 X-SA-Exim-Version: 4.2 X-SA-Exim-Scanned: Yes (on mail.dannysplace.net) Subject: Re: IPFW Mac filter confusion. X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 02 Aug 2007 12:47:47 -0000 Andrey V. Elsukov wrote: > From ipfw(8): > net.link.ether.ipfw: 0 > Controls whether layer-2 packets are passed to ipfw. Default is no. > > Do you change this option to 1? Missed that bit. I did not read the packet flow part, just toe format of the MAC option. It is now enabled and working as described... -D