From owner-freebsd-ipfw@FreeBSD.ORG Fri Feb 24 10:12:24 2006 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BABE616A420; Fri, 24 Feb 2006 10:12:24 +0000 (GMT) (envelope-from joao@matik.com.br) Received: from msrv.matik.com.br (msrv.matik.com.br [200.152.83.14]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1692F43D46; Fri, 24 Feb 2006 10:12:23 +0000 (GMT) (envelope-from joao@matik.com.br) Received: from anb (anb.matik.com.br [200.152.83.34]) by msrv.matik.com.br (8.13.4/8.13.1) with ESMTP id k1OACM2q068916; Fri, 24 Feb 2006 07:12:22 -0300 (BRT) (envelope-from joao@matik.com.br) From: JoaoBR To: freebsd-ipfw@freebsd.org Date: Fri, 24 Feb 2006 07:12:21 -0300 User-Agent: KMail/1.9.1 References: <200602200300.k1K30TZr050863@freefall.freebsd.org> <200602240630.53797.joao@matik.com.br> In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Message-Id: <200602240712.21502.joao@matik.com.br> X-Filter-Version: 1.11a (msrv.matik.com.br) X-Virus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on msrv.matik.com.br X-Virus-Status: Clean Cc: Hajimu UMEMOTO Subject: Re: kern/93422: Re: ipfw divert rule X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 24 Feb 2006 10:12:24 -0000 On Friday 24 February 2006 06:41, Hajimu UMEMOTO wrote: > > joao> ipfw add 1000 divert 8669 dst-ip 0.0.0.0 src-ip 0.0.0.0 > > joao> work than? > > It should work. > > joao> How should I rewrite my rules or better regressing to the old "ip f= rom=20 > any to=20 > joao> any" ? > It should work as expected, too. =A0You need to pay attention to the use > of `ip', `ipv4' and `ipv6' with `proto' keyword. well, then according to the proto-ip-thing this =20 ipfw add deny proto ip dst-ip ${DSTIP} not src-ip ${SRCIP} should not work correctly but it counts : =2E. 36 3612 deny ip from any to any dst-ip ... not src-ip ... so? Jo=E3o A mensagem foi scaneada pelo sistema de e-mail e pode ser considerada segura. Service fornecido pelo Datacenter Matik https://datacenter.matik.com.br