Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 14 Feb 2004 20:01:07 -0600
From:      Eric F Crist <ecrist@adtechintegrated.com>
To:        freebsd-questions@freebsd.org
Cc:        Jez Hancock <jez.hancock@munk.nu>
Subject:    Re: continued IPFW issues... (actually a lack of ability on my part)
Message-ID:  <200402142001.13194.ecrist@adtechintegrated.com>
In-Reply-To: <20040215015007.GA53079@falcon.midgard.homeip.net>
References:  <20040214233615.GB38665@users.munk.nu> <200402141942.38712.ecrist@adtechintegrated.com> <20040215015007.GA53079@falcon.midgard.homeip.net>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
My bad, I found the log entry after your prodding.  After enabling logging in 
the ruleset and enabling the sysctl variable, I get the following output in a 
tail /var/log/security:

Feb 14 19:59:44 grog kernel: ipfw: 65534 Deny UDP 192.168.0.1:51598 
255.255.255.255:61112 in via dc0
Feb 14 19:59:45 grog kernel: ipfw: 65534 Deny UDP 204.147.80.1:53 
63.228.14.241:49152 in via dc0
Feb 14 19:59:46 grog kernel: ipfw: 65534 Deny UDP 204.127.202.4:53 
63.228.14.241:49152 in via dc0
Feb 14 19:59:50 grog kernel: ipfw: 65534 Deny UDP 192.168.0.1:51599 
255.255.255.255:61112 in via dc0
Feb 14 19:59:55 grog kernel: ipfw: 65534 Deny UDP 204.127.202.4:53 
63.228.14.241:49152 in via dc0
Feb 14 19:59:56 grog kernel: ipfw: 65534 Deny UDP 192.168.0.1:51600 
255.255.255.255:61112 in via dc0
Feb 14 19:59:59 grog kernel: ipfw: 65534 Deny UDP 204.147.80.5:53 
63.228.14.241:49152 in via dc0
Feb 14 20:00:02 grog kernel: ipfw: 65534 Deny UDP 204.147.80.5:53 
63.228.14.241:49152 in via dc0
Feb 14 20:00:02 grog kernel: ipfw: 65534 Deny UDP 192.168.0.1:51601 
255.255.255.255:61112 in via dc0
Feb 14 20:00:03 grog kernel: ipfw: 65534 Deny UDP 204.147.80.1:53 
63.228.14.241:49152 in via dc0

I would assume I need to enable a rule such as:

ipfw add allow udp from any to me 53

Is this correct?  TIA

-- 
Eric F Crist
AdTech Integrated Systems, Inc
(612) 998-3588

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQBALtLpzdyDbTMRQIYRAkEcAJ0bp0JGNqG+yMFH9XYQA8r1ukXDPQCeNx2P
IQNBIq3WvG1MRK+4nT4mEr4=
=L38Y
-----END PGP SIGNATURE-----
help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200402142001.13194.ecrist>