Vexing IPF problem

2005-06-17 Thread DH
I'm having a problem with IPF blocking packets that appear should be let through. I've sent quite a bit of time going through the Handbook, man pages, etc I must be missing something so any help is greatly appriciated. uname -a freebsd 4.11-release #0 SMP kernel, dual PIII processor, 512

RE: Vexing IPF problem

2005-06-17 Thread fbsd_user
] [mailto:[EMAIL PROTECTED] Behalf Of DH Sent: Friday, June 17, 2005 11:13 AM To: freebsd-questions@freebsd.org Subject: Vexing IPF problem I'm having a problem with IPF blocking packets that appear should be let through. I've sent quite a bit of time going through the Handbook, man pages, etc I must

Re: Vexing IPF problem

2005-06-17 Thread John Conner
Hello David, Im not expert on IPF but on first inspeciton it would look like the problem is in your first fxp0 rule: block in log quick on fxp0 from any to any with ipopts To the best of my knowledge when quick is added the firewall does not look at any of the other rules. If this is the case

RE: Vexing IPF problem

2005-06-17 Thread DH
: Vexing IPF problem I'm having a problem with IPF blocking packets that appear should be let through. I've sent quite a bit of time going through the Handbook, man pages, etc I must be missing something so any help is greatly appriciated. uname -a freebsd 4.11-release #0 SMP kernel, dual PIII

Re: Vexing IPF problem

2005-06-17 Thread John Conner
David, If you just REM'd the ipopts rule the firewall will stop at the next line: block in log quick proto tcp from any to any with short Try commenting out both these lines as the quick in the second rule would also cause the firewall to reject incoming traffic. Using quick tells the firewall

Re: Vexing IPF problem

2005-06-17 Thread horio shoichi
On Fri, 17 Jun 2005 08:12:45 -0700 (PDT) DH [EMAIL PROTECTED] wrote: I'm having a problem with IPF blocking packets that appear should be let through. I've sent quite a bit of time going through the Handbook, man pages, etc I must be missing something so any help is greatly appriciated.