Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 5 May 2002 13:56:55 +0800
From:      Eugene Grosbein <eugen@D00015.dialonly.kemerovo.su>
To:        "William J. Borskey" <wborskey@hotmail.com>
Cc:        security@FreeBSD.ORG
Subject:   Re: ipfw
Message-ID:  <20020505135655.A320@grosbein.pp.ru>
In-Reply-To: <F93OUDxTcg2yWsqdiDu00006aa0@hotmail.com>; from wborskey@hotmail.com on Sat, May 04, 2002 at 08:36:52PM -0700
References:  <F93OUDxTcg2yWsqdiDu00006aa0@hotmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, May 04, 2002 at 08:36:52PM -0700, William J. Borskey wrote:

> is it possible to write rules for ipfw using ethernet addresses instead of 
> ip addresses?

You can have frozen ARP table and use ip addresses for ipfw
to achieve the same effect. Check this out:
http://www.FreeBSD.org/cgi/query-pr.cgi?pr=kern/36373

We use sort of that in production.

Eugene Grosbein
  

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020505135655.A320>