Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 29 Apr 2005 16:10:33 +0200
From:      "Nagy Istvan" <nagy.istvan1@chello.hu>
To:        "Siddhartha Jain" <sid@netmagicsolutions.com>, <freebsd-security@freebsd.org>
Subject:   Re: IPFW disconnections and resets
Message-ID:  <005f01c54cc5$36ab6e40$0200a8c0@PIHP>
References:  <4272011F.9040707@netmagicsolutions.com>

next in thread | previous in thread | raw e-mail | index | archive | help

Hi,

im playing with the /etc/crontab to reload the rules periodically, while i 
remotly edit both crontab and ipfw_rules.sh, this solves the problem of 
lock-out (but i dont know exactly what other problems it might cause...:)

sshd_config has a ClientAliveInterval (seconds between trys) and 
ClientAliveCountMax (how many times to try keepalive, before client known as 
nonrespondig and disconnected) option, and on the client side as ~Neo-Vortex
wrote find the keepalive setting. (and if the client is untrustable, disable 
it >:)

Istvan


----- Original Message ----- 
From: "Siddhartha Jain" <sid@netmagicsolutions.com>
To: <freebsd-security@freebsd.org>
Sent: Friday, April 29, 2005 11:40 AM
Subject: IPFW disconnections and resets


> Hi,
>
> I am using IPFW on FreeBSD 4.11
>
> I am facing two problems:
> - SSH sessions timeout after a while
> - When I run "/sbin/ipfw -q -f flush" in the rules script all connection
> get reset (and I am thrown out of the box).
>
> Is this standard functioning of ipfw or do I need to change any
> configuration?
>
>
> Thanks,
>
> Siddhartha
>
>
> _______________________________________________
> freebsd-security@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to 
> "freebsd-security-unsubscribe@freebsd.org"
>
>
> -- 
> No virus found in this incoming message.
> Checked by AVG Anti-Virus.
> Version: 7.0.308 / Virus Database: 266.10.4 - Release Date: 2005.04.27.
>
> 




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?005f01c54cc5$36ab6e40$0200a8c0>