Smart questions
Smart answers
Smart people
INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Member Login

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips now!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

Join Tek-Tips
*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

LINK TO THIS FORUM!

Add Stickiness To Your Site By Linking To This Professionally Managed Technical Forum.
Just copy and paste the
code below into your site.

Partner With Us!

"Best Of Breed" Forums Add Stickiness To Your Site
Partner Button
(Download This Button Today!)

Feedback

"...I signed up to your site to get help with a problem and I am so glad I did. I found the help I needed immediately. Thanks to all who contribute to your site..."

Geography

Where in the world do Tek-Tips members come from?
aios (ISP)
13 Dec 04 7:38
OK, I am new to freeBSD, but I'm not a firewall newb. The setup looks like this - 3 wireless cards (ap mode)bridged with an Ethernet, ipwf enabled. Kernel's compiled without default_to_accept option.
Ethernet nic is then wired to another Linux box that handles hotspot authentification, daily quotas and other user related stuff.
Now, the problem pops up when I try to filter the traffic on FreeBSD. The general idea is to allow udp traffic on port 67 to 68 (dhcp traffic) form any to any as well as icmp traffic (for testing network connectivity). ICMP ping doesn't get trough with option "allow icmp from any to any", and sometimes the funniest thing happens - 10 packets go trough and the rest of them get dropped!
option "allow { not tcp or not udp } form any to any" passes all traffic trough!
anyone got an idea what am I doing wrong?

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Back To Forum

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close