From owner-freebsd-net@FreeBSD.ORG Wed Mar 19 20:47:55 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 38E8F106564A for ; Wed, 19 Mar 2008 20:47:55 +0000 (UTC) (envelope-from julian@elischer.org) Received: from outK.internet-mail-service.net (outK.internet-mail-service.net [216.240.47.234]) by mx1.freebsd.org (Postfix) with ESMTP id 1DFC68FC24 for ; Wed, 19 Mar 2008 20:47:54 +0000 (UTC) (envelope-from julian@elischer.org) Received: from mx0.idiom.com (HELO idiom.com) (216.240.32.160) by out.internet-mail-service.net (qpsmtpd/0.40) with ESMTP; Wed, 19 Mar 2008 13:48:12 -0700 Received: from julian-mac.elischer.org (localhost [127.0.0.1]) by idiom.com (Postfix) with ESMTP id CE3482D601F; Wed, 19 Mar 2008 13:47:53 -0700 (PDT) Message-ID: <47E17BF9.1030403@elischer.org> Date: Wed, 19 Mar 2008 13:47:53 -0700 From: Julian Elischer User-Agent: Thunderbird 2.0.0.12 (Macintosh/20080213) MIME-Version: 1.0 To: Freddie Cash References: <200803191334.54510.fjwcash@gmail.com> In-Reply-To: <200803191334.54510.fjwcash@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-net@freebsd.org Subject: Re: "established" on { tcp or udp } rules X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Mar 2008 20:47:55 -0000 Freddie Cash wrote: > Just curious if the following rule will work correctly. It is accepted by > the ipfw command. In the process of working out a test for it, but > thought I'd ask here as well, just to be sure. > > ipfw add { tcp or udp } from me to any 53 out xmit fxp0 > ipfw add { tcp or udp } from any 53 to me in recv fxp0 established > > Will the UDP packets go through correctly, even though "established" has > no meaning for UDP streams, and the ipfw command will barf if you use it > with just "ipfw add udp" rules? > well, an action to do would be good.. as for the question of whether UDP ... established evaluates to true or false, I would guess false but you'll have to test.