Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 24 Oct 2001 09:47:04 +0200
From:      "Patrick O'Reilly" <patrick@mip.co.za>
To:        "Diego" <diego@bcgames.com.br>, <freebsd-questions@FreeBSD.ORG>
Subject:   RE: problem with ip_fw_ctl!
Message-ID:  <NDBBIMKICMDGDMNOOCAIAEAGDMAA.patrick@mip.co.za>
In-Reply-To: <000001c15c46$b88562e0$b7ddbfc8@drean>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Diego,

Did you also add:
options         IPDIVERT
to your kernel config?

My kernel config for firewalls is usually like so:
options         IPFIREWALL                        #firewall
options         IPFIREWALL_VERBOSE      #print information about
options         IPFIREWALL_FORWARD     #enable transparent proxy support
options         IPDIVERT                            #divert sockets
options         DUMMYNET

See LINT.

Regards,
Patrick.
  -----Original Message-----
  From: owner-freebsd-questions@FreeBSD.ORG
[mailto:owner-freebsd-questions@FreeBSD.ORG]On Behalf Of Diego
  Sent: 24 October 2001 06:45
  To: freebsd-questions@FreeBSD.ORG
  Subject: problem with ip_fw_ctl!


  I need help i recompile my kernel with all options about FIREWALL...but
ipdivert and forward not work, send this message

  Oct 24 02:14:09 bcgames /kernel: ip_fw_ctl: invalid command

  My sysctl:
  kern.maxfiles: 32808
  kern.maxfilesperproc: 32808
  net.inet.ip.maxfragpackets: 4224
  kern.maxusers: 1024
  -> I find that he is correct


  I do not know more what to make!

  thank´s

  I wait reply



[-- Attachment #2 --]
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=iso-8859-1" http-equiv=Content-Type>
<META content="MSHTML 5.00.3103.1000" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001>Diego,</SPAN></FONT></DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN class=781544207-24102001>Did 
you also add:</SPAN></FONT></DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
IPDIVERT</SPAN></FONT></DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN class=781544207-24102001>to 
your kernel config?</SPAN></FONT></DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN class=781544207-24102001>My 
kernel config for firewalls is usually like so:</SPAN></FONT></DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
IPFIREWALL&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
#firewall<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
IPFIREWALL_VERBOSE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #print information 
about<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
IPFIREWALL_FORWARD&nbsp;&nbsp;&nbsp;&nbsp; #enable transparent proxy 
support<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
IPDIVERT&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #divert 
sockets<BR>options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 
DUMMYNET<BR></SPAN></FONT></DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN class=781544207-24102001>See 
LINT.</SPAN></FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV>Regards,</SPAN></FONT></DIV>
<DIV><FONT color=#0000ff face=Arial size=2><SPAN 
class=781544207-24102001>Patrick.</DIV></SPAN></FONT>
<BLOCKQUOTE 
style="BORDER-LEFT: #0000ff 2px solid; MARGIN-LEFT: 5px; MARGIN-RIGHT: 0px; PADDING-LEFT: 5px">
  <DIV align=left class=OutlookMessageHeader dir=ltr><FONT face=Tahoma 
  size=2>-----Original Message-----<BR><B>From:</B> 
  owner-freebsd-questions@FreeBSD.ORG 
  [mailto:owner-freebsd-questions@FreeBSD.ORG]<B>On Behalf Of 
  </B>Diego<BR><B>Sent:</B> 24 October 2001 06:45<BR><B>To:</B> 
  freebsd-questions@FreeBSD.ORG<BR><B>Subject:</B> problem with 
  ip_fw_ctl!<BR><BR></DIV></FONT>
  <DIV><FONT face=Arial size=2>I&nbsp;need help i recompile my kernel with all 
  options about FIREWALL...but ipdivert and forward not work, send this 
  message</FONT></DIV>
  <DIV>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>Oct 24 02:14:09 bcgames /kernel: ip_fw_ctl: 
  invalid command</FONT></DIV>
  <DIV>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>My sysctl:</FONT></DIV>
  <DIV><FONT face=Arial size=2>kern.maxfiles: 32808<BR>kern.maxfilesperproc: 
  32808<BR>net.inet.ip.maxfragpackets: 4224</FONT></DIV>
  <DIV><FONT face=Arial size=2>kern.maxusers: 1024</FONT></DIV>
  <DIV><FONT face=Arial size=2>-&gt; I find that he is correct<BR></FONT></DIV>
  <DIV>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>I do not know more what to make!</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>thank´s</FONT></DIV>
  <DIV><FONT face=Arial size=2>&nbsp;</FONT></DIV>
  <DIV><FONT face=Arial size=2>I wait 
reply<BR><BR></DIV></BLOCKQUOTE></FONT></BODY></HTML>

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?NDBBIMKICMDGDMNOOCAIAEAGDMAA.patrick>