From owner-freebsd-questions@FreeBSD.ORG Tue May 24 11:54:50 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5607716A41C for ; Tue, 24 May 2005 11:54:50 +0000 (GMT) (envelope-from joost@jodocus.org) Received: from bps.jodocus.org (g157016.upc-g.chello.nl [80.57.157.16]) by mx1.FreeBSD.org (Postfix) with ESMTP id C94D243D1D for ; Tue, 24 May 2005 11:54:49 +0000 (GMT) (envelope-from joost@jodocus.org) Received: from jodocus.org (localhost [127.0.0.1]) by bps.jodocus.org (8.13.3/8.13.1) with ESMTP id j4OBsjTm067223; Tue, 24 May 2005 13:54:45 +0200 (CEST) (envelope-from joost@jodocus.org) Received: (from joost@localhost) by jodocus.org (8.13.3/8.13.1/Submit) id j4OBsjGG067222; Tue, 24 May 2005 13:54:45 +0200 (CEST) (envelope-from joost) Date: Tue, 24 May 2005 13:54:45 +0200 From: Joost Bekkers To: Chris Knipe Message-ID: <20050524115445.GA67204@bps.jodocus.org> Mail-Followup-To: Joost Bekkers , Chris Knipe , freebsd-questions@freebsd.org References: <20050524105605.GA37881@savage.za.org> <20050524113858.GA38897@savage.za.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20050524113858.GA38897@savage.za.org> User-Agent: Mutt/1.4.2.1i Cc: freebsd-questions@freebsd.org Subject: Re: ipf + ipfw + divert = no go X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 May 2005 11:54:50 -0000 On Tue, May 24, 2005 at 01:38:58PM +0200, Chris Knipe wrote: > On Tue, May 24, 2005 at 12:56:06PM +0200, Chris Knipe wrote: > > Hi, > > > > Quick question... > > > > dmesg: > > IP Filter: v3.4.35 initialized. Default = pass all, Logging = enabled > > ipfw2 initialized, divert enabled, rule-based forwarding enabled, default to accept, logging limited to 1024 packets/entry by default > > > > > > shell: > > bash-2.05b# ipfw add 50 fwd 192.168.0.237,3306 tcp from any to x.x.56.178 dst-port 3306 > > ipfw: getsockopt(IP_FW_ADD): Operation not permitted > > bash-2.05b# whoami > > root > > bash-2.05b# > > > > What gives????? FreeBSD 5.4-STABLE > > > bash-2.05b# ipfw add 50 fwd 1.1.1.1,1 tcp from 1.1.1.1 to 1.1.1.1 dst-port 1 > ipfw: getsockopt(IP_FW_ADD): Operation not permitted > bash-2.05b# ipfw add 50 allow ip from me to any > ipfw: getsockopt(IP_FW_ADD): Operation not permitted > bash-2.05b# At what securelevel are you running? You can use 'sysctl kern.securelevel' to check. -- greetz Joost joost@jodocus.org