Date: Fri, 4 Mar 2005 01:21:11 +0530 From: "Subhro" <subhro.kar@gmail.com> To: "'Paul Schmehl'" <pauls@utdallas.edu>, "'FreeBSD questions'" <freebsd-questions@freebsd.org> Subject: RE: ipfw lost its mind? Message-ID: <42276ab8.5a7f85a2.4c2a.3e73@smtp.gmail.com> In-Reply-To: <E879B29E7D463AD4CA8D4543@utd49554.utdallas.edu>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --]
Do you block UDP?
I am asking this because, I *used* do a block on all UDP except the DNS port
and had exactly the same problem.
Regards
S.
Indian Institute of Information Technology
Subhro Sankha Kar
Block AQ-13/1, Sector V
Salt Lake City
PIN 700091
India
> -----Original Message-----
> From: owner-freebsd-questions@freebsd.org [mailto:owner-freebsd-
> questions@freebsd.org] On Behalf Of Paul Schmehl
> Sent: Friday, March 04, 2005 1:09
> To: FreeBSD questions
> Subject: Re: ipfw lost its mind?
>
> --On Thursday, March 03, 2005 01:48:16 PM -0500 Chuck Swiger
> <cswiger@mac.com> wrote:
> >
> > TCP connections are bidirectional, therefore you need to add rules which
> > allow traffic from all back to your workstation, or else use keep-state
> > and check-state to use dynamic rules....
>
> The firewall script already had a rule for that:
> allow ip from {server} to any
>
> The problem wasn't that the firewall was *stopping* legitimate packets.
> It
> was just *slowing them down* like crazy. Very weird.
>
> Paul Schmehl (pauls@utdallas.edu)
> Adjunct Information Security Officer
> The University of Texas at Dallas
> AVIEN Founding Member
> http://www.utdallas.edu
> _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "freebsd-questions-
> unsubscribe@freebsd.org"
[-- Attachment #2 --]
0 *H
010 + 0 *H
0=0 ͺVT"rU0
*H
0_10 UUS10U
VeriSign, Inc.1705U.Class 1 Public Primary Certification Authority0
960129000000Z
280801235959Z0_10 UUS10U
VeriSign, Inc.1705U.Class 1 Public Primary Certification Authority00
*H
0 mVa-Hqg뷞
8%Fs$]
enVsߴX9knը?144g NEVixG)6c\-{2{0*/1g 0
*H
L?hC3]Mz36ؕ"6hl|B.?OvJ͠
)"]݁#{%F0yK@<_SH䆴{5{%ӎ?8 4 q0f0Ϡ
O[uj)0
*H
0_10 UUS10U
VeriSign, Inc.1705U.Class 1 Public Primary Certification Authority0
980512000000Z
080512235959Z010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated00
*H
0 ZDUz-Ox6
JoTw*h1ApzKHV-BD\B/;'
]6B3nTOJƚj$e~7jJ 00 `HB05U.0,0*(&$http://crl.verisign.com/pca1.1.1.crl0GU @0>0<`HE0-0++www.verisign.com/repository/RPA0U0 0U0
*H
B|ߌyLMU/P^N.^2yeJRը1!l4x BZъު"!e3 3
>5d$[h|7d
Ž33>>s020:N4fr40
*H
010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated0
041111000000Z
050718235959Z010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. by Ref.,LIAB.LTD(c)9810UPersona Not Validated1402U+Digital ID Class 1 - Microsoft Full Service10U
Subhro Kar1#0! *H
subhro.kar@gmail.com00
*H
0 )Fp["
,9Uڵ87(v0r1C.\4VP@h!"r(
⎅?-"2K 00 U0 0DU =0;09`HE0*0(+https://www.verisign.com/rpa0U0U%0++0
`HENone03U,0*0(&$"http://crl.verisign.com/class1.crl0
*H
]5羧n-A$NyiIk{}Y(DKTHE@&mZK#TEWO.bqƼsE $raEsh{Os{[=zz_,v߈QԊ>1>0:0010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated:N4fr40 + 0 *H
1 *H
0 *H
1
050303195110Z0# *H
1)D|kC10g *H
1Z0X0
*H
0*H
0
*H
@0+0
*H
(0+0
*H
0 +710010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated:N4fr40*H
1䠁010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated:N4fr40
*H
%h7[֯t}CSE#DE_"/B5iyl=me&m~^Z0xlfxN)gx--g\) 4E@I8ڄ)[
help
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?42276ab8.5a7f85a2.4c2a.3e73>
