From owner-freebsd-questions  Tue Sep 25 19:56: 1 2001
Delivered-To: freebsd-questions@freebsd.org
Received: from cody.jharris.com (cody.jharris.com [205.238.128.83])
	by hub.freebsd.org (Postfix) with ESMTP id 1CF2F37B40F
	for <freebsd-questions@FreeBSD.ORG>; Tue, 25 Sep 2001 19:55:57 -0700 (PDT)
Received: from localhost (nick@localhost)
	by cody.jharris.com (8.11.1/8.9.3) with ESMTP id f8Q2tob47626;
	Tue, 25 Sep 2001 21:55:50 -0500 (CDT)
	(envelope-from nick@rogness.net)
Date: Tue, 25 Sep 2001 21:55:50 -0500 (CDT)
From: Nick Rogness <nick@rogness.net>
X-Sender: nick@cody.jharris.com
To: Brian Whalen <bri@sonicboom.org>
Cc: David Kelly <dkelly@hiwaay.net>,
	Bradley Oedithipus <bradley@lightstep.org>,
	freebsd-questions@FreeBSD.ORG
Subject: Re: natd/ipfw/sshd problem. 
In-Reply-To: <20010925194752.S61552-100000@cx175057-a.ocnsd1.sdca.home.com>
Message-ID: <Pine.BSF.4.21.0109252152420.47372-100000@cody.jharris.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Sender: owner-freebsd-questions@FreeBSD.ORG
Precedence: bulk
List-ID: <freebsd-questions.FreeBSD.ORG>
List-Archive: <http://docs.freebsd.org/mail/> (Web Archive)
List-Help: <mailto:majordomo@FreeBSD.ORG?subject=help> (List Instructions)
List-Subscribe: <mailto:majordomo@FreeBSD.ORG?subject=subscribe%20freebsd-questions>
List-Unsubscribe: <mailto:majordomo@FreeBSD.ORG?subject=unsubscribe%20freebsd-questions>
X-Loop: FreeBSD.ORG

On Tue, 25 Sep 2001, Brian Whalen wrote:

> Is anyone doing anything about that??

	Why, the default is to deny.

[snip]
> > > I find it interesting that somehow 27 packets got past 65000. Can only
> > > assume not all of the above rules were added at the same time.
> >
> > 	It is possible for packets to arrive before the firewall rules get
> > 	loaded.


Nick Rogness <nick@rogness.net>
 - Keep on Routing in a Free World...
  "FreeBSD: The Power to Serve!"


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message