From owner-freebsd-stable@FreeBSD.ORG Thu Mar 24 12:20:21 2005 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7716516A4CE for ; Thu, 24 Mar 2005 12:20:21 +0000 (GMT) Received: from ene.asda.gr (ene.asda.gr [193.92.118.161]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0944A43D54 for ; Thu, 24 Mar 2005 12:20:21 +0000 (GMT) (envelope-from lefty@ene.asda.gr) Received: by ene.asda.gr (Postfix, from userid 127) id D69B911416; Thu, 24 Mar 2005 14:20:17 +0200 (EET) Received: from ene.asda.gr (lefty.ene.asda.gr [193.92.118.162]) (using SSLv3 with cipher RC4-MD5 (128/128 bits))OK)) by ene.asda.gr (Postfix) with ESMTP id 7D12411411 for ; Thu, 24 Mar 2005 14:20:13 +0200 (EET) Message-ID: <4242B07C.DD76A610@ene.asda.gr> Date: Thu, 24 Mar 2005 14:20:12 +0200 From: Lefteris Tsintjelis Organization: ASDA X-Mailer: Mozilla 4.8 [en] (Windows NT 5.0; U) X-Accept-Language: en,el MIME-Version: 1.0 To: freebsd-stable@freebsd.org Content-Type: text/plain; charset=iso-8859-7 Content-Transfer-Encoding: 7bit X-Spam-Checker-Version: SpamAssassin 3.0.2 (2004-11-16) on ene.asda.gr Subject: Denied broadcast packets in same interface with antispoofing X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Mar 2005 12:20:21 -0000 FreeBSD 5.4-PRERELEASE #0: Thu Mar 17 16:41:58 EET 2005 ${fwcmd} add 400 deny log ip from any to any not antispoof in rl2: flags=8843 mtu 1500 inet 192.168.0.97 netmask 0xffffffe0 broadcast 192.168.0.127 /var/log/security: ipfw: 400 Deny ICMP:8.0 192.168.0.97 192.168.0.96 in via rl2 ipfw: 400 Deny ICMP:8.0 192.168.0.97 192.168.0.96 in via rl2 ipfw: 400 Deny ICMP:8.0 192.168.0.97 192.168.0.127 in via rl2 ipfw: 400 Deny ICMP:8.0 192.168.0.97 192.168.0.127 in via rl2 ipfw: 400 Deny UDP 192.168.0.97:123 192.168.0.127:123 in via rl2 Why are broadcast packets originating from the same interface are denied access? Am I missing something here? Thanks in advance, Lefteris Tsintjelis