From owner-freebsd-ipfw@FreeBSD.ORG Mon Dec 8 20:28:52 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E59FC16A4CE for ; Mon, 8 Dec 2003 20:28:52 -0800 (PST) Received: from publicd.ub.mng.net (publicd.ub.mng.net [202.179.0.88]) by mx1.FreeBSD.org (Postfix) with ESMTP id C0C5943D2C for ; Mon, 8 Dec 2003 20:28:50 -0800 (PST) (envelope-from ganbold@micom.mng.net) Received: from [202.179.0.164] (helo=ganbold.micom.mng.net) by publicd.ub.mng.net with asmtp (Exim 4.24; FreeBSD 5.1) id 1ATZR9-000GeW-3p; Tue, 09 Dec 2003 12:25:27 +0800 Message-Id: <6.0.0.22.2.20031209122902.02a58840@202.179.0.80> X-Sender: ganbold@micom.mng.net@202.179.0.80 X-Mailer: QUALCOMM Windows Eudora Version 6.0.0.22 Date: Tue, 09 Dec 2003 12:32:07 +0800 To: Don Bowman From: Ganbold In-Reply-To: References: Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed cc: freebsd-ipfw@freebsd.org Subject: RE: bridged ipfw problem in FreeBSD 5.2beta X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 Dec 2003 04:28:53 -0000 Hi, Thank you for all who helped me. It seems that arp packets weren't pass through firewall. I added the rule as don suggested and since then it is working well for last 25 hours. Ganbold At 10:26 PM 05.12.2003, you wrote: >From: Ganbold [mailto:ganbold@micom.mng.net] > > ... bridging firewall ... > > ># Allowing connections through localhost. > >${fwcmd} add 300 pass all from any to any via lo0 > ># pass ARP > >${fwcmd} add 301 pass udp from 0.0.0.0 2054 to 0.0.0.0 > >the comment at least is not right, arp is not udp. > >maybe something like "add 301 allow layer2 mac-type arp" >instead? > >--don