From owner-freebsd-questions@FreeBSD.ORG Tue Apr 18 01:24:25 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 702EC16A401 for ; Tue, 18 Apr 2006 01:24:25 +0000 (UTC) (envelope-from list-freebsd-2004@morbius.sent.com) Received: from out1.smtp.messagingengine.com (out1.smtp.messagingengine.com [66.111.4.25]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1743D43D46 for ; Tue, 18 Apr 2006 01:24:24 +0000 (GMT) (envelope-from list-freebsd-2004@morbius.sent.com) Received: from frontend2.internal (frontend2.internal [10.202.2.151]) by frontend1.messagingengine.com (Postfix) with ESMTP id F06BED4C1DC for ; Mon, 17 Apr 2006 21:24:22 -0400 (EDT) Received: from frontend3.messagingengine.com ([10.202.2.152]) by frontend2.internal (MEProxy); Mon, 17 Apr 2006 21:23:52 -0400 X-Sasl-enc: i7sgubH+kx60fMVWVEs9Kw+vIun345MKH1FojzqgmW0V 1145323432 Received: from bb-87-81-140-128.ukonline.co.uk (bb-87-81-140-128.ukonline.co.uk [87.81.140.128]) by frontend3.messagingengine.com (Postfix) with ESMTP id 0212C3D26 for ; Mon, 17 Apr 2006 21:23:51 -0400 (EDT) From: RW To: freebsd-questions@freebsd.org Date: Tue, 18 Apr 2006 02:24:19 +0100 User-Agent: KMail/1.9.1 References: <8921D35B-1F12-4212-9B62-0CC1CC8F5AE5@allresearch.com> In-Reply-To: <8921D35B-1F12-4212-9B62-0CC1CC8F5AE5@allresearch.com> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200604180224.20749.list-freebsd-2004@morbius.sent.com> Subject: Re: IPFW Problems X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Apr 2006 01:24:25 -0000 On Monday 17 April 2006 22:29, Noah Silverman wrote: > ipfw add 0430 allow log tcp from any to me 22 in via bge0 setup limit > src-addr 2 > ipfw add 00499 deny log all from any to any in via bge0 > > In theory, this should allow in SSH and nothing else. > What happens when you replace "limit src-addr 2" with keep-state? If that works replace it with "limit src-addr 200" and work down/