Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 14 Feb 2001 22:13:02 +0100
From:      Stefan <roijers@iae.nl>
To:        nate@yogotech.com (Nate Williams)
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Abnormal behaviour of "established" rule with ipfw?
Message-ID:  <4.1.20010214220858.009477a0@pop.iae.nl>
In-Reply-To: <14986.61927.680205.227406@nomad.yogotech.com>
References:  <4.1.20010214211242.0094ac90@pop.iae.nl> <4.1.20010214211242.0094ac90@pop.iae.nl>

next in thread | previous in thread | raw e-mail | index | archive | help
At 14:00 14-2-01 -0700, Nate Williams wrote:
>Were these packets from connections setup before the firewall rule was
>in place?  If so, they are already established.

No, as far as I can see really setup packets can pass through.
My firewall was accepting incoming telnet when there was a 
deny all from any to any in via xl0 setup 
line after the allow established from any to any line.

Stefan



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4.1.20010214220858.009477a0>