From owner-freebsd-security@FreeBSD.ORG Fri Jun 20 05:49:27 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C3A2F37B401 for ; Fri, 20 Jun 2003 05:49:27 -0700 (PDT) Received: from dire.bris.ac.uk (dire.bris.ac.uk [137.222.10.60]) by mx1.FreeBSD.org (Postfix) with ESMTP id EE71F43F3F for ; Fri, 20 Jun 2003 05:49:26 -0700 (PDT) (envelope-from Jan.Grant@bristol.ac.uk) Received: from mail.ilrt.bris.ac.uk by dire.bris.ac.uk with SMTP-PRIV with ESMTP; Fri, 20 Jun 2003 13:49:20 +0100 Received: from cmjg (helo=localhost) by mail.ilrt.bris.ac.uk with local-esmtp (Exim 3.16 #1) id 19TLIU-0005Ej-00; Fri, 20 Jun 2003 13:47:18 +0100 Date: Fri, 20 Jun 2003 13:47:18 +0100 (BST) From: Jan Grant X-X-Sender: cmjg@mail.ilrt.bris.ac.uk To: Jim Hatfield In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: Jan Grant cc: freebsd-security@freebsd.org Subject: Re: IPFW: combining "divert natd" with "keep-state" X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Jun 2003 12:49:28 -0000 On Fri, 20 Jun 2003, Jim Hatfield wrote: [there was more] > >: ipfw add 300 deny ip from 192.168.0.0/16 to any in via rl0 > >: ipfw add 300 deny ip from any to 192.168.0.0/16 in via rl0 > But one question first: do you > ever get hits on the second rule 300? I would have thought > it very difficult for anyone to route a packet to you with > a non-routable destination address. Surely only your ISP > could do that? Do you trust your ISP? If the choice is between a rule that has no benefit providing everyone configured their stuff correctly, and leaving out the safety-net because you expect to not need it, that's a pretty simple choice. -- jan grant, ILRT, University of Bristol. http://www.ilrt.bris.ac.uk/ Tel +44(0)117 9287088 Fax +44 (0)117 9287112 http://ioctl.org/jan/ Goth isn't dead, it's just lying very still and sucking its cheeks in.