Date: Tue, 9 Dec 2003 17:41:45 +0800 From: <chael@southgate.ph.inter.net> To: <freebsd-questions@freebsd.org> Subject: Re: ipfw keep-state (ASAP anwser need) Message-ID: <001601c3be38$a9333fa0$fe01a8c0@JMICH> References: <20031209093254.GA366@profi.kharkov.ua>
next in thread | previous in thread | raw e-mail | index | archive | help
${fwcmd} add allow udp from any 1024-65535,53 to any 53 ${fwcmd} add allow udp from any 53 to any 1024-65535 ----- Original Message ----- From: "Gregory Edigarov" <greg@profi.kharkov.ua> To: <freebsd-questions@freebsd.org> Sent: Tuesday, December 09, 2003 5:32 PM Subject: ipfw keep-state (ASAP anwser need) > Hello, > > The folowing is a fragment of my rc.firewall which must allow all > traffic in and out of my named. > > ---- > ipfw add 4100 allow udp from me to any 53 keep-state > ipfw add 4200 allow udp from any to me 53 > ipfw add 4300 allow udp from me 53 to any > --- > This is a fragment from my kernel configuration: > --- > options IPFIREWALL #firewall > options IPFIREWALL_VERBOSE #enable logging to > syslogd(8) > options IPFIREWALL_FORWARD #enable transparent proxy > support > options IPFIREWALL_VERBOSE_LIMIT=100 #limit verbosity > options IPDIVERT #divert sockets > options IPSTEALTH > options ICMP_BANDLIM > options DUMMYNET > options BRIDGE > options IPFW2 > --- > It doesn't work. What am I missing? > > -- > With best regards, > Gregory Edigarov > -------------------------------------------------------------------------- ---- > profi.kharkov.ua Systems Administrator > -------------------------------------------------------------------------- ---- > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org" > >
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?001601c3be38$a9333fa0$fe01a8c0>