From owner-freebsd-current@FreeBSD.ORG Thu Feb 24 01:31:14 2005 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id ECDFE16A4CF for ; Thu, 24 Feb 2005 01:31:13 +0000 (GMT) Received: from mail.tellme3times.com (dsl-yul-102.e-scape.net [209.47.218.102]) by mx1.FreeBSD.org (Postfix) with ESMTP id CF09643D49 for ; Thu, 24 Feb 2005 01:31:12 +0000 (GMT) (envelope-from chris@tellme3times.com) Received: from [192.168.7.29] (halla.tellme3times.com [192.168.7.29]) by mail.tellme3times.com (Postfix) with ESMTP id 565804376 for ; Wed, 23 Feb 2005 20:21:13 -0500 (EST) Message-ID: <421D2EE4.7030905@tellme3times.com> Date: Wed, 23 Feb 2005 20:33:24 -0500 From: Chris User-Agent: Mozilla Thunderbird 1.0 (X11/20050205) X-Accept-Language: en-us, en MIME-Version: 1.0 To: freebsd-current@freebsd.org Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: PPPoE and 5.1 to 5.3 Upgrade X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Feb 2005 01:31:14 -0000 I upgraded my firewall from 5.1 to RELENG 5.3. Everything went fairly well. First I would like to thank everyone for their efforts in producing this graet OS. I have a few minor problems. One is ppp nat which worked fine under 5.1 fails under 5.3. The system has acces to the net as I am able to send this out but it does not allow any other systems access. If I can get this to run I'll research my answers to the other problems. Here are the rules which worked under 5.1. I built the kernel with netgraph and pppoe. set filter alive 0 permit tcp set filter dial 0 permit 0 0 udp dst eq 53 set filter dial 1 permit 0 0 tcp dst eq http set filter dial 2 permit 0 0 tcp dst eq login set filter dial 3 permit 0 0 tcp dst eq shell set filter dial 4 permit 0 0 tcp dst eq telnet set filter dial 5 permit 0 0 tcp dst eq ftp set filter dial 6 permit 0 0 tcp dst eq 22 set filter dial 7 deny ! 0 0 tcp dst eq 4000 set filter in 0 permit 0/0 0/0 tcp estab set filter in 1 permit 0/0 0/0 tcp dst eq 22 set filter in 2 permit 0/0 0/0 tcp dst eq 25 set filter in 3 permit 0/0 0/0 tcp dst eq 53 set filter in 4 permit 0/0 0/0 udp dst eq 53 set filter in 5 permit 0/0 0/0 tcp dst eq 80 set filter in 6 permit 0/0 0/0 tcp src eq 143 set filter in 7 permit xx.xx.xx.xx/32 0/0 set filter in 8 permit xx.xx.xx.xx/32 0/0 set filter in 9 permit 0/0 0/0 icmp src eq 3 set filter in 10 permit 0/0 0/0 icmp src eq 4 set filter in 11 permit 0/0 0/0 icmp src eq 11 set filter in 12 permit 0/0 0/0 icmp src eq 12 set filter in 13 permit 0/0 0/0 icmp src eq 0 any help would be appreciated. Thank you