Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 10 Aug 2001 21:11:53 -0400
From:      James Housley <jim@thehousleys.net>
To:        George Genovezos <ggenovez@hotmail.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: ipfw & firewall.
Message-ID:  <3B748659.E2D96F11@Thehousleys.net>
References:  <F111mKldz8axXzTx7Sx000064dd@hotmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
George Genovezos wrote:
> 
> Hey all,
> 
> I just installed ipfw and the only thing I want to go in & out is ssh. So
> this is the only line I have in my rules
> 
> allow tcp from any to any ssh setup
> 
> Now when I ssh to my localhost I get
> 
> debug: Allocated local port 881.
> debug: connect: Connection refused
> debug: Connecting to localhost [127.0.0.1] port 22.
> debug: Allocated local port 880.
> debug: connect: Permission denied
> 

Actually you want something like the following

allow tcp from any to any established
allow tcp from any ssh to any out setup
allow tcp from any to any ssh in setup

You probably also want to allow udp 53 both ways, for DNS?

Jim
-- 
/"\   ASCII Ribbon Campaign  .
\ / - NO HTML/RTF in e-mail  .
 X  - NO Word docs in e-mail .
/ \ -----------------------------------------------------------------
jeh@FreeBSD.org      http://www.FreeBSD.org     The Power to Serve
jim@TheHousleys.Net  http://www.TheHousleys.net
---------------------------------------------------------------------
Life begins at 4.0

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3B748659.E2D96F11>