From owner-freebsd-security@FreeBSD.ORG Wed Mar 26 15:45:17 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0F22C37B404 for ; Wed, 26 Mar 2003 15:45:17 -0800 (PST) Received: from lament.noc.uk.easynet.net (lament.noc.uk.easynet.net [195.40.7.149]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8288343F75 for ; Wed, 26 Mar 2003 15:45:16 -0800 (PST) (envelope-from ben@lament.noc.uk.easynet.net) Received: by lament.noc.uk.easynet.net (Postfix, from userid 1001) id 153DA961; Wed, 26 Mar 2003 23:45:15 +0000 (GMT) Date: Wed, 26 Mar 2003 23:45:14 +0000 From: Ben Hughes To: freebsd-security@freebsd.org Message-ID: <20030326234514.GA33356@uk.easynet.net> References: <3E82386C.000003.20487@ns.interchange.ca> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <3E82386C.000003.20487@ns.interchange.ca> User-Agent: Mutt/1.4.1i X-Living: The Dream(tm) X-Stop: Reading the X-Headers, you really must be bored. X-Spam-Status: No, hits=-31.2 required=5.0 tests=EMAIL_ATTRIBUTION,IN_REP_TO,NO_DNS_FOR_FROM, QUOTED_EMAIL_TEXT,REFERENCES,REPLY_WITH_QUOTES, USER_AGENT_MUTT autolearn=ham version=2.50 X-Spam-Level: X-Spam-Checker-Version: SpamAssassin 2.50 (1.173-2003-02-20-exp) X-Mailman-Approved-At: Wed, 26 Mar 2003 15:52:36 -0800 cc: Michael Richards Subject: Re: Multiple Firewalls with ipfilter? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 26 Mar 2003 23:45:23 -0000 On Wed, Mar 26, 2003 at 06:31:56PM -0500, Michael Richards wrote: > 2) I need a means of syncing the state info so existing connections > won't be torn down if they end up going through the other firewall. I've often thought about using /sbin/ipfs over a serial cable/link, or a modified version therein.. No idea if it's doable, but it's a really rather pleasant idea (: -- Ben Hughes, | False sense of Security Dept.