Re: [gentoo-user] Re: OT: iptables mac filtering

2006-08-11 Thread Richard Fish
On 8/10/06, James [EMAIL PROTECTED] wrote: I need a rule on the 3 (nic) interface firewall so that only ssh from the LAN is allowed to the firewall or sytems (web server, mail dns) in the DMZ. Only one static ip is routable to this site. SSH from the outside should be completely blocked. Any

[gentoo-user] Re: OT: iptables mac filtering

2006-08-11 Thread James
Richard Fish bigfish at asmallpond.org writes: I need a rule on the 3 (nic) interface firewall so that only ssh from the LAN is allowed to the firewall or sytems (web server, mail dns) in the DMZ. Only one static ip is routable to this site. SSH from the outside should be completely

[gentoo-user] Re: OT: iptables mac filtering

2006-08-11 Thread James
Richard Fish bigfish at asmallpond.org writes: On 8/11/06, James wireless at tampabay.rr.com wrote: myIP hackIPTCP 55634 smtp (SYN) Seq=0 ACK=1 WIN=0 LEN=0 hackIP myIP TCP smtp 55634 (RST,ACK) Seq=0 ACK=1 WIN=0 LEN=0 MSS=1460 Assuming you haven't mixed up the myIP and hackIP