From owner-freebsd-questions@FreeBSD.ORG Sun Feb 13 13:20:32 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0B58916A4CE for ; Sun, 13 Feb 2005 13:20:32 +0000 (GMT) Received: from nagual.st (cc20684-a.assen1.dr.home.nl [217.122.132.217]) by mx1.FreeBSD.org (Postfix) with ESMTP id E53C543D45 for ; Sun, 13 Feb 2005 13:20:30 +0000 (GMT) (envelope-from dick@nagual.st) Received: from pooh.nagual.st (pooh.nagual.st [192.168.11.22]) by nagual.st with esmtp; Sun, 13 Feb 2005 14:19:14 +0100 Date: Sun, 13 Feb 2005 14:20:36 +0100 From: dick hoogendijk To: freebsd-questions@freebsd.org Message-Id: <20050213142036.09fb3b72.dick@nagual.st> Organization: nagual SiTe X-Mailer: Sylpheed version 1.0.1 (GTK+ 1.2.10; i386-portbld-freebsd4.11) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: ipfilter and ntp sserver X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 13 Feb 2005 13:20:32 -0000 I want my local ntp server up and running, so I put in /etc/rc.conf: xntpd_enable="YES" but waht are the right rules for ipfilter? Someting like: # Allow out ntp traffic pass out quick on rl0 proto tcp from any to any port = 123 flags S keep state pass out quick on rl0 proto udp from any to any port = 123 keep state Or do I have to open some ports incoming as well? [ I think I need a good book about ipfilter ;-) ] I mentioned tcp/udp because I read in /etc/services that ntp uses both. Does keep state mean that automagically all incoming traffic will be OK (for ntp) -- dick -- http://nagual.st/ -- PGP/GnuPG key: F86289CE ++ Running FreeBSD 4.11 ++ FreeBSD 5.3 + Nai tiruvantel ar vayuvantel i Valar tielyanna nu vilja