From owner-freebsd-questions@FreeBSD.ORG Tue Aug 12 19:41:25 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6AB5537B401 for ; Tue, 12 Aug 2003 19:41:25 -0700 (PDT) Received: from franky.speednet.com.au (franky.speednet.com.au [203.57.65.5]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4052443F93 for ; Tue, 12 Aug 2003 19:41:24 -0700 (PDT) (envelope-from andyf@speednet.com.au) Received: from hewey.af.speednet.com.au (hewey.af.speednet.com.au [203.38.96.242])h7D2fFkO016069; Wed, 13 Aug 2003 12:41:15 +1000 (EST) (envelope-from andyf@speednet.com.au) Received: from hewey.af.speednet.com.au (hewey.af.speednet.com.au [203.38.96.242])h7D2fDHT091113; Wed, 13 Aug 2003 12:41:14 +1000 (EST) (envelope-from andyf@speednet.com.au) Date: Wed, 13 Aug 2003 12:41:13 +1000 (EST) From: Andy Farkas X-X-Sender: andyf@hewey.af.speednet.com.au To: Mark In-Reply-To: <200308120022.H7C0MGXS058078@asarian-host.net> Message-ID: <20030813123805.Y90272-100000@hewey.af.speednet.com.au> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-questions@freebsd.org Subject: Re: Restricting ICMP X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 13 Aug 2003 02:41:25 -0000 > > Is there a way I can use ipfw to disallow ICMP from anyone, but root? > (FreeBSD 4.7R) I tried this: > > ${fwcmd} -q add 4 allow icmp from any to any icmptype 0,3,8,11 in via > ${outside} > ${fwcmd} -q add 4 allow icmp from any to any uid root > ${fwcmd} -q add 4 deny log icmp from any to any man ipfw says: uid user Match all TCP or UDP packets sent by or received for a user. A user may be matched by name or identification number. ..which sort of implies it wont work for icmp. Why would you want this policy? -- :{ andyf@speednet.com.au Andy Farkas System Administrator Speednet Communications http://www.speednet.com.au/