From owner-freebsd-stable@FreeBSD.ORG Wed Nov 10 14:22:47 2004 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CE69B16A4CE for ; Wed, 10 Nov 2004 14:22:47 +0000 (GMT) Received: from sccrmhc12.comcast.net (sccrmhc12.comcast.net [204.127.202.56]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4F4A043D53 for ; Wed, 10 Nov 2004 14:22:47 +0000 (GMT) (envelope-from imbutler@comcast.net) Received: from auburn.comcast.net (h000086489e8c.ne.client2.attbi.com[66.31.37.42]) by comcast.net (sccrmhc12) with ESMTP id <2004111014224601200rjiade>; Wed, 10 Nov 2004 14:22:46 +0000 Received: from localhost (unknown [127.0.0.1]) by auburn.comcast.net (Postfix) with ESMTP id D5D091706B for ; Wed, 10 Nov 2004 09:22:45 -0500 (EST) Received: from auburn.comcast.net ([127.0.0.1]) by localhost (auburn.comcast.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 74993-03 for ; Wed, 10 Nov 2004 09:22:39 -0500 (EST) Received: from 192.168.1.12 (localhost.comcast.net [127.0.0.1]) by auburn.comcast.net (Postfix) with ESMTP for ; Wed, 10 Nov 2004 09:22:39 -0500 (EST) Received: from 192.168.1.10 (SquirrelMail authenticated user imb); by h000086489e8c.ne.client2.attbi.com with HTTP; Wed, 10 Nov 2004 09:22:39 -0500 (EST) Message-ID: <2894.192.168.1.10.1100096559.squirrel@192.168.1.10> In-Reply-To: <20041110140614.GO85877@weirdos.oban.frmug.org> References: <20041110134853.GB87953@sr.se> <20041110140614.GO85877@weirdos.oban.frmug.org> Date: Wed, 10 Nov 2004 09:22:39 -0500 (EST) From: "Michael Butler" To: "FreeBSD Stable" User-Agent: SquirrelMail/1.4.3a X-Mailer: SquirrelMail/1.4.3a MIME-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 Content-Transfer-Encoding: 8bit X-Priority: 3 (Normal) Importance: Normal X-Virus-Scanned: at auburn.comcast.net Subject: Re: 5.3-RELEASE kde 3.3 and pf X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 10 Nov 2004 14:22:47 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > Maybe you should allow everything on lo0, in and out. 127/8 should always be allowed on the loopback interface, 127/8 should always be dropped from all other interfaces. I am "uncomfortable" saying that everything should be allowed .. Michael Butler CISSP Security Consultant Savvis Communications www.savvis.net PGP Key ID: 0x5E873CC5 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (FreeBSD) iD8DBQFBkiQviJykeV6HPMURAuGvAKCxPvD2JBnymAZi6DSGv+h39whQoQCfSp+x TmQ7x0bqDw49rGjemk8WQUg= =Y6/E -----END PGP SIGNATURE-----